ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.

Project Subscriptions

Vendors Products
Canonical Subscribe
Ubuntu Linux Subscribe
Debian Linux Subscribe
Ansible Subscribe
Ansible Engine Subscribe
Enterprise Linux Desktop Subscribe
Enterprise Linux Server Subscribe
Enterprise Linux Workstation Subscribe
Openstack Subscribe
Linux Enterprise Subscribe
Package Hub Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-4396-1 ansible security update
EUVD EUVD EUVD-2019-0002 ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.
Github GHSA Github GHSA GHSA-j569-fghw-f9rx Ansible sensitive information disclosure
Ubuntu USN Ubuntu USN USN-4072-1 Ansible vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-05T10:32:54.241Z

Reserved: 2018-09-11T00:00:00.000Z

Link: CVE-2018-16876

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-01-03T15:29:01.163

Modified: 2024-11-21T03:53:30.457

Link: CVE-2018-16876

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-12-07T00:00:00Z

Links: CVE-2018-16876 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses