Information disclosure in Ansible - CVE-2018-16837
Published: November 5, 2018
Vulnerability identifier: #VU15721
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16837
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to Ansible "User" module exposes data passed as parameter to ssh-keygen. A local user with ability to view process list can obtain sensitive information.
Affected software
Ansible
ansible (Alpine package)
ansible
Fedora
SUSE Linux
Opensuse
SUSE Package Hub for SUSE Linux Enterprise
ansible (Alpine package)
ansible
Fedora
SUSE Linux
Opensuse
SUSE Package Hub for SUSE Linux Enterprise
How to mitigate CVE-2018-16837
Install updates from vendor's website.
Ansible - addressed in versions 2.5.11, 2.6.7, 2.7.1
ansible (Alpine package) - update to 2.5.15-r0
ansible - update to 2.6.7-1.el6
ansible (Alpine package) - update to 2.5.15-r0
ansible - update to 2.6.7-1.el6