V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2018-16837
AST
High

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as pas…

CVSS
7.8
High
EPSS
0.00
p7
Published
2018-01-01
Updated
2018-01-01
Description

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.

Tags · CWE
CWE-214
Affected products
AnsibleAnsibleAnsibleAnsibleAnsibleAnsibleAnsibleAnsibleAnsibleAnsibleAnsibleAnsibleAnsibleAnsibleAnsibleAnsibleAnsibleAnsibleAnsibleAnsible
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Timeline
2018-01-01
Published
2018-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.000 · p7
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
ansibleTracked
ansibleTracked
ansibleTracked
ansibleTracked
ansibleTracked
ansibleTracked
ansibleTracked
ansibleTracked
ansibleTracked
ansibleTracked
ansibleTracked
ansibleTracked
ansibleTracked
ansibleTracked
ansibleTracked
ansibleTracked
ansibleTracked
ansibleTracked
ansibleTracked
ansibleTracked
Source databases
AST
DEB
CVE
RED
UBU
Related vulnerabilities