CVE-2018-16837: High severity redhat Ansible Engine vulnerability
"User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-16837?
CVE-2018-16837 is a vulnerability in the Ansible "User" module that leaks any data passed as a parameter to ssh-keygen.
What is the severity level of CVE-2018-16837?
The severity level of CVE-2018-16837 is high.
Which software versions are affected by CVE-2018-16837?
The affected software versions include Ansible 2.5.1, 2.8.0, 2.0.0.2-2ubuntu1.3, 2.7.1, 2.6.7, and Redhat Ansible Engine 2.0, 2.5, 2.6, 2.7, and Redhat Ansible Tower 3.3.0.
How can I fix CVE-2018-16837?
To fix CVE-2018-16837, update Ansible to versions 2.7.7+dfsg-1+deb10u1, 2.10.7+merged+base+2.10.8+dfsg-1, 7.3.0+dfsg-1, or 7.7.0+dfsg-3.
Where can I find more information about CVE-2018-16837?
You can find more information about CVE-2018-16837 at the following references: [MITRE CVE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16837), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16837), and [Ansible GitHub Pull Request](https://github.com/ansible/ansible/pull/47436).