Information disclosure in Ansible - CVE-2018-16859

 

Information disclosure in Ansible - CVE-2018-16859

Published: December 5, 2018 / Updated: December 6, 2018


Vulnerability identifier: #VU16312
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16859
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker with administrative privileges to obtain potentially sensitive information.

The vulnerability exists due to the plaintext exposure of “become” passwords when Ansible playbooks are executed on a Windows system with PowerShell scriptblock logging and module logging. A local attacker can discover the plaintext password that can be used to conduct further attacks.


Affected software

Ansible
ansible (Alpine package)
Red Hat Ansible Engine
SUSE Package Hub for SUSE Linux Enterprise
SUSE Linux
Opensuse

How to mitigate CVE-2018-16859

The vulnerability has been fixed in the versions 2.5.13, 2.6.10, 2.7.4.

Ansible - addressed in versions 2.5.13, 2.6.10, 2.7.4, 2.5.13-1.el7ae, 2.6.10-1.el7ae, 2.7.4-1.el7ae

External References

Related Security Bulletins