First published: Thu Nov 17 2016(Updated: )
An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
pip/ansible | >=0<2.2.1.0 | 2.2.1.0 |
Red Hat Ansible Engine | <2.2.1.0 | |
Red Hat Enterprise Virtualization | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8647 is rated as a low severity vulnerability.
CVE-2016-8647 affects Ansible versions prior to 2.2.1.0, specifically the mysql_user module.
To fix CVE-2016-8647, upgrade Ansible to version 2.2.1.0 or later.
CVE-2016-8647 may lead to failures in password changes for MySQL users, leaving old passwords active.
No, CVE-2016-8647 is not classified as a critical vulnerability, but it may still pose a risk depending on the configuration.