#VU12837 Information disclosure through log files in Ansible - CVE-2018-1117
Published: May 15, 2018 / Updated: May 18, 2018
Ansible
Red Hat Inc.
Description
The vulnerability allows a local attacker to obtain potentially sensitive information on the target system.
The weakness exists due to a missing no_log directive, the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclose admin passwords in the provisioning log. A local attacker can gain access to potentially sensitive information.