CVE-2018-16837
published 2018-10-23CVE-2018-16837: Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials…
PriorityP337high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.35%
27.7th percentile
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 2.7.1+dfsg-1 (bookworm) | ansible 2.7.1+dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| redhat | ansible | >= 0 < 2.7.1+dfsg-1 | 2.7.1+dfsg-1 |
| redhat | ansible | >= 0 < 2.7.1+dfsg-1 | 2.7.1+dfsg-1 |
| redhat | ansible | >= 0 < 2.7.1+dfsg-1 | 2.7.1+dfsg-1 |
| redhat | ansible | >= 0 < 2.7.1+dfsg-1 | 2.7.1+dfsg-1 |
| redhat | ansible | >= 0 < 2.5.11 | 2.5.11 |
| redhat | ansible | >= 0 < 2.0.0.2-2ubuntu1.3 | 2.0.0.2-2ubuntu1.3 |
| redhat | ansible | >= 0 < 2.5.1+dfsg-1ubuntu0.1 | 2.5.1+dfsg-1ubuntu0.1 |
| redhat | ansible | >= 2.6.0a1 < 2.6.7 | 2.6.7 |
| redhat | ansible | >= 2.7.0a1 < 2.7.1 | 2.7.1 |
| redhat | ansible_engine | — | — |
| redhat | ansible_engine | — | — |
| redhat | ansible_engine | — | — |
| redhat | ansible_engine | — | — |
| redhat | ansible_tower | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ansible vulnerabilities
vendor_ubuntu·2019-07-24·CVSS 9.8
CVE-2017-7481 [CRITICAL] Ansible vulnerabilities
Title: Ansible vulnerabilities
Summary: Several security issues were fixed in Ansible.
It was discovered that Ansible failed to properly handle sensitive information.
A local attacker could use those vulnerabilities to extract them.
(CVE-2017-7481)
(CVE-2018-10855)
(CVE-2018-16837)
(CVE-2018-16876)
(CVE-2019-10156)
It was discovered that Ansible could load configuration files from the current
working directory containing crafted commands. An attacker could run arbitrary
code as result.
(CVE-2018-10874)
(CVE-2018-10875)
It was discovered that Ansible fetch module had a path traversal vulnerability.
A local attacker could copy and overwrite files outside of the specified
destination.
(CVE-2019-3828)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
Ansible: Information leak in "user" module
vendor_redhat·2018-10-23·CVSS 7.8
CVE-2018-16837 [HIGH] CWE-214 Ansible: Information leak in "user" module
Ansible: Information leak in "user" module
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.
The User module in Ansible leaks any data which is passed on as a parameter to ssh-keygen. This could lead to undesirable situations such as passphrase credentials being passed as a parameter for the ssh-keygen executable, showing those credentials in clear text form for every user which have access just to the process list.
Statement: This issue affects the version of ansible as shipped with Red Hat Ceph Storage 3, as it contains th
Debian
CVE-2018-16837: ansible - Ansible "User" module leaks any data which is passed on as a parameter to ssh-ke...
vendor_debian·2018·CVSS 7.8
CVE-2018-16837 [HIGH] CVE-2018-16837: ansible - Ansible "User" module leaks any data which is passed on as a parameter to ssh-ke...
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.
Scope: local
bookworm: resolved (fixed in 2.7.1+dfsg-1)
bullseye: resolved (fixed in 2.7.1+dfsg-1)
forky: resolved (fixed in 2.7.1+dfsg-1)
sid: resolved (fixed in 2.7.1+dfsg-1)
trixie: resolved (fixed in 2.7.1+dfsg-1)
GHSA
Ansible Leaks Data Passed to ssh-keygen
ghsa·2022-05-13
CVE-2018-16837 [HIGH] CWE-311 Ansible Leaks Data Passed to ssh-keygen
Ansible Leaks Data Passed to ssh-keygen
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.
OSV
Ansible Leaks Data Passed to ssh-keygen
osv·2022-05-13
CVE-2018-16837 [HIGH] Ansible Leaks Data Passed to ssh-keygen
Ansible Leaks Data Passed to ssh-keygen
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.
OSV
ansible vulnerabilities
osv·2019-07-24·CVSS 9.8
CVE-2017-7481 [CRITICAL] ansible vulnerabilities
ansible vulnerabilities
It was discovered that Ansible failed to properly handle sensitive information.
A local attacker could use those vulnerabilities to extract them.
(CVE-2017-7481)
(CVE-2018-10855)
(CVE-2018-16837)
(CVE-2018-16876)
(CVE-2019-10156)
It was discovered that Ansible could load configuration files from the current
working directory containing crafted commands. An attacker could run arbitrary
code as result.
(CVE-2018-10874)
(CVE-2018-10875)
It was discovered that Ansible fetch module had a path traversal vulnerability.
A local attacker could copy and overwrite files outside of the specified
destination.
(CVE-2019-3828)
OSV
CVE-2018-16837: Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen
osv·2018-10-23·CVSS 7.8
CVE-2018-16837 [HIGH] CVE-2018-16837: Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00077.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00020.htmlhttp://www.securityfocus.com/bid/105700https://access.redhat.com/errata/RHSA-2018:3460https://access.redhat.com/errata/RHSA-2018:3461https://access.redhat.com/errata/RHSA-2018:3462https://access.redhat.com/errata/RHSA-2018:3463https://access.redhat.com/errata/RHSA-2018:3505https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16837https://lists.debian.org/debian-lts-announce/2018/11/msg00012.htmlhttps://usn.ubuntu.com/4072-1/https://www.debian.org/security/2019/dsa-4396https://access.redhat.com/security/cve/cve-2018-16837http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00077.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00020.htmlhttp://www.securityfocus.com/bid/105700https://access.redhat.com/errata/RHSA-2018:3460https://access.redhat.com/errata/RHSA-2018:3461https://access.redhat.com/errata/RHSA-2018:3462https://access.redhat.com/errata/RHSA-2018:3463https://access.redhat.com/errata/RHSA-2018:3505https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16837https://lists.debian.org/debian-lts-announce/2018/11/msg00012.htmlhttps://usn.ubuntu.com/4072-1/https://www.debian.org/security/2019/dsa-4396
2018-10-23
Published