Information disclosure in Ansible - CVE-2018-16837

 

Information disclosure in Ansible - CVE-2018-16837

Published: November 5, 2018


Vulnerability identifier: #VU15721
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16837
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to Ansible "User" module exposes data passed as parameter to ssh-keygen. A local user with ability to view process list can obtain sensitive information.


Affected software

Ansible
ansible (Alpine package)
ansible
Fedora
SUSE Linux
Opensuse
SUSE Package Hub for SUSE Linux Enterprise

How to mitigate CVE-2018-16837

Install updates from vendor's website.

Ansible - addressed in versions 2.5.11, 2.6.7, 2.7.1
ansible (Alpine package) - update to 2.5.15-r0
ansible - update to 2.6.7-1.el6

External References

Related Security Bulletins