CVE-2016-8647: Input Validation
An input validation vulnerability was found in Ansible's mysqluser module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed.
Other sources
It is reported that in Ansible, under some circumstances the mysqluser module may fail to correctly change a password. Thus an old password may still be active when it should have been changed.
External References: https://github.com/ansible/ansible-modules-core/pull/5388
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8647?
CVE-2016-8647 is rated as a low severity vulnerability.
What types of software are affected by CVE-2016-8647?
CVE-2016-8647 affects Ansible versions prior to 2.2.1.0, specifically the mysql_user module.
How do I fix CVE-2016-8647?
To fix CVE-2016-8647, upgrade Ansible to version 2.2.1.0 or later.
What does CVE-2016-8647 vulnerability impact?
CVE-2016-8647 may lead to failures in password changes for MySQL users, leaving old passwords active.
Is CVE-2016-8647 a critical vulnerability?
No, CVE-2016-8647 is not classified as a critical vulnerability, but it may still pose a risk depending on the configuration.