Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-16837

Опубликовано: 23 окт. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.1
CVSS3: 7.8

Описание

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.

РелизСтатусПримечание
bionic

released

2.5.1+dfsg-1ubuntu0.1
cosmic

ignored

end of life
devel

not-affected

2.7.5+dfsg-1
disco

not-affected

2.7.5+dfsg-1
eoan

not-affected

2.7.5+dfsg-1
esm-apps/bionic

released

2.5.1+dfsg-1ubuntu0.1
esm-apps/focal

not-affected

2.7.5+dfsg-1
esm-apps/jammy

not-affected

2.7.5+dfsg-1
esm-apps/noble

not-affected

2.7.5+dfsg-1
esm-apps/xenial

released

2.0.0.2-2ubuntu1.3

Показывать по

EPSS

Процентиль: 12%
0.0004
Низкий

2.1 Low

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
больше 7 лет назад

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.

CVSS3: 7.8
nvd
больше 7 лет назад

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.

CVSS3: 7.8
debian
больше 7 лет назад

Ansible "User" module leaks any data which is passed on as a parameter ...

CVSS3: 7.8
github
больше 3 лет назад

Ansible Leaks Data Passed to ssh-keygen

CVSS3: 7.8
fstec
больше 7 лет назад

Уязвимость модуля «User» системы управления конфигурациями Ansible, связанная с раскрытием данных, передаваемых в качестве параметров утилите ssh-keygen, позволяющая нарушителю получить несанкционированный доступ к конфиденциальной информации пользователя

EPSS

Процентиль: 12%
0.0004
Низкий

2.1 Low

CVSS2

7.8 High

CVSS3