CVE-2016-8647
published 2018-07-26CVE-2016-8647: An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain…
PriorityP423medium4.9CVSS 3.1
AVNACLPRHUINSUCNIHAN
EPSS
1.43%
70.0th percentile
An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 2.2.0.0-4 (bookworm) | ansible 2.2.0.0-4 (bookworm) |
| red_hat | ansible | — | — |
| redhat | ansible | >= 0 < 2.2.0.0-4 | 2.2.0.0-4 |
| redhat | ansible | >= 0 < 2.2.0.0-4 | 2.2.0.0-4 |
| redhat | ansible | >= 0 < 2.2.0.0-4 | 2.2.0.0-4 |
| redhat | ansible | >= 0 < 2.2.0.0-4 | 2.2.0.0-4 |
| redhat | ansible | >= 0 < 2.2.1.0 | 2.2.1.0 |
| redhat | ansible_engine | < 2.2.1.0 | 2.2.1.0 |
| redhat | virtualization | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
nvdv3.02.2LOWCVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Ansible: in some circumstances the mysql_user module may fail to correctly change a password
vendor_redhat·2016-10-26·CVSS 4.9
CVE-2016-8647 [MEDIUM] CWE-20 Ansible: in some circumstances the mysql_user module may fail to correctly change a password
Ansible: in some circumstances the mysql_user module may fail to correctly change a password
An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed.
An input validation vulnerability was found in Ansible's mysql_user module which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed.
Package: ansible (Red Hat OpenShift Enterprise 3) - Affected
Package: ansible (Red Hat OpenStack Platform 10 (Newton)) - Not affected
Package: ansible (Red Hat OpenStack Platform 11 (Ocata)) - Not affected
Package: ansible (R
Debian
CVE-2016-8647: ansible - An input validation vulnerability was found in Ansible's mysql_user module befor...
vendor_debian·2016·CVSS 4.9
CVE-2016-8647 [MEDIUM] CVE-2016-8647: ansible - An input validation vulnerability was found in Ansible's mysql_user module befor...
An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed.
Scope: local
bookworm: resolved (fixed in 2.2.0.0-4)
bullseye: resolved (fixed in 2.2.0.0-4)
forky: resolved (fixed in 2.2.0.0-4)
sid: resolved (fixed in 2.2.0.0-4)
trixie: resolved (fixed in 2.2.0.0-4)
GHSA
Improper Input Validation in ansible
ghsa·2018-10-10
CVE-2016-8647 [MEDIUM] CWE-20 Improper Input Validation in ansible
Improper Input Validation in ansible
An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed.
OSV
Improper Input Validation in ansible
osv·2018-10-10
CVE-2016-8647 [MEDIUM] Improper Input Validation in ansible
Improper Input Validation in ansible
An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed.
OSV
CVE-2016-8647: An input validation vulnerability was found in Ansible's mysql_user module before 2
osv·2018-07-26·CVSS 4.9
CVE-2016-8647 [MEDIUM] CVE-2016-8647: An input validation vulnerability was found in Ansible's mysql_user module before 2
An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9587 Ansible: Compromised remote hosts can lead to running commands on the Ansible controller [epel-all]
bugzilla·2017-01-11·CVSS 8.1
CVE-2016-9587 [HIGH] CVE-2016-9587 Ansible: Compromised remote hosts can lead to running commands on the Ansible controller [epel-all]
CVE-2016-9587 Ansible: Compromised remote hosts can lead to running commands on the Ansible controller [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
Bugzilla
CVE-2016-8647 Ansible: in some circumstances the mysql_user module may fail to correctly change a password [epel-all]
bugzilla·2016-11-17·CVSS 4.9
CVE-2016-8647 [MEDIUM] CVE-2016-8647 Ansible: in some circumstances the mysql_user module may fail to correctly change a password [epel-all]
CVE-2016-8647 Ansible: in some circumstances the mysql_user module may fail to correctly change a password [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2016-8647 Ansible: in some circumstances the mysql_user module may fail to correctly change a password [fedora-all]
bugzilla·2016-11-17·CVSS 4.9
CVE-2016-8647 [MEDIUM] CVE-2016-8647 Ansible: in some circumstances the mysql_user module may fail to correctly change a password [fedora-all]
CVE-2016-8647 Ansible: in some circumstances the mysql_user module may fail to correctly change a password [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
Bugzilla
CVE-2016-8647 Ansible: in some circumstances the mysql_user module may fail to correctly change a password
bugzilla·2016-11-17·CVSS 4.9
CVE-2016-8647 [MEDIUM] CVE-2016-8647 Ansible: in some circumstances the mysql_user module may fail to correctly change a password
CVE-2016-8647 Ansible: in some circumstances the mysql_user module may fail to correctly change a password
It is reported that in Ansible, under some circumstances the mysql_user module may fail to correctly change a password. Thus an old password may still be active when it should have been changed.
External References:
https://github.com/ansible/ansible-modules-core/pull/5388
Discussion:
Created ansible tracking bugs for this issue:
Affects: fedora-all [bug 1396175]
---
Created ansible tracking bugs for this issue:
Affects: epel-all [bug 1396176]
---
This was actually fixed in ansible-2.2.1.0 which was pushed a while back. ;(
---
(In reply to Kevin Fenzi from comment #4)
> This was actually fixed in ansible-2.2.1.0 which was pushed a while back. ;(
Please, don't close the bu
https://access.redhat.com/errata/RHSA-2017:1685https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8647https://github.com/ansible/ansible-modules-core/pull/5388https://access.redhat.com/errata/RHSA-2017:1685https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8647https://github.com/ansible/ansible-modules-core/pull/5388
2018-07-26
Published