CVE-2018-16859
Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext.
Does this matter?
Lower severity and a low EPSS score (0.54%). Track it; it rarely justifies an emergency change on its own.
Description
Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. Ansible Engine 2.8 and older are believed to be vulnerable.
- CVSS 3.0
- 4.4 MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.54% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- redhat/ansible engine
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00021.html
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00077.html
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00020.html
- http://www.securityfocus.com/bid/106004Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3770Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3771Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3772Issue Tracking, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3773Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16859Issue Tracking, Vendor Advisory
- https://github.com/ansible/ansible/pull/49142Patch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00021.html
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00077.html
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00020.html
- http://www.securityfocus.com/bid/106004Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3770Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3771Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3772Issue Tracking, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3773Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16859Issue Tracking, Vendor Advisory
- https://github.com/ansible/ansible/pull/49142Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.