Описание
Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. Ansible Engine 2.8 and older are believed to be vulnerable.
Execution of Ansible content on Microsoft's Windows platform with Powershell 5 or higher may disclose sensitive execution details including 'become' passwords, Ansible module arguments, and return values via Powershell's 'suspicious scriptblock logging' feature, which is enabled by default. The details are logged to the Powershell Operational log, which is visible to all authenticated users by default.
Отчет
CloudForms and Satellite 6 are not affected by this issue, since Microsoft Windows is not a supported platform.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| CloudForms Management Engine 5 | ansible | Not affected | ||
| Red Hat Ceph Storage 2 | ansible | Affected | ||
| Red Hat Ceph Storage 3 | ansible | Affected | ||
| Red Hat OpenShift Container Platform 3.2 | ansible | Not affected | ||
| Red Hat OpenShift Container Platform 3.3 | ansible | Not affected | ||
| Red Hat OpenShift Container Platform 3.4 | ansible | Will not fix | ||
| Red Hat OpenShift Container Platform 3.5 | ansible | Will not fix | ||
| Red Hat OpenShift Container Platform 3.6 | ansible | Will not fix | ||
| Red Hat OpenShift Container Platform 3.7 | ansible | Affected | ||
| Red Hat OpenShift Enterprise 3.0 | ansible | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
4.2 Medium
CVSS3
Связанные уязвимости
Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. Ansible Engine 2.8 and older are believed to be vulnerable.
Execution of Ansible playbooks on Windows platforms with PowerShell Sc ...
Ansible Logs Passwords If PowerShell ScriptBlock is Enabled
EPSS
4.2 Medium
CVSS3