SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-16859

Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext.

MEDIUM 4.4EPSS 0.54%

Does this matter?

Lower severity and a low EPSS score (0.54%). Track it; it rarely justifies an emergency change on its own.

Description

Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. Ansible Engine 2.8 and older are believed to be vulnerable.

CVSS 3.0
4.4 MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS
0.54% probability · 44th percentile
CISA KEV
Not listed
Weakness
CWE-532
Affected
redhat/ansible engine
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.