Information disclosure in Ansible - CVE-2018-16859
Published: December 5, 2018 / Updated: December 6, 2018
Vulnerability details
The vulnerability allows a local attacker with administrative privileges to obtain potentially sensitive information.
The vulnerability exists due to the plaintext exposure of “become” passwords when Ansible playbooks are executed on a Windows system with PowerShell scriptblock logging and module logging. A local attacker can discover the plaintext password that can be used to conduct further attacks.
Affected software
ansible (Alpine package)
Red Hat Ansible Engine
SUSE Package Hub for SUSE Linux Enterprise
SUSE Linux
Opensuse
How to mitigate CVE-2018-16859
External References
Related Security Bulletins
- Information disclosure in Red Hat Ansible
- OpenSUSE Linux update for ansible
- OpenSUSE Linux update for ansible
- OpenSUSE Linux update for ansible
- OpenSUSE Linux update for ansible
- OpenSUSE Linux update for ansible
- Information disclosure in ansible (Alpine package)
- Ansible Engine 2.5 update for ansible
- Ansible Engine 2.6 update for ansible
- Ansible Engine 2 update for ansible
- Ansible Engine 2.7 update for ansible