CVE-2018-16876: Infoleak
ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with nolog on that can lead to leakage of sensible data.
Other sources
ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with nolog on that can lead to leakage of sensible data.
— Launchpad
It was found that when a retry task in ansible run with -vvv fails, it will log the raw return code, stdout and stderr from ssh which could have contained sensitive data.
Upstream patch:
https://github.com/ansible/ansible/pull/49569/commits/4c6d714aefb05366cb329e139214c89ebb364899
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this Ansible vulnerability?
The vulnerability ID of this Ansible vulnerability is CVE-2018-16876.
What is the severity level of CVE-2018-16876?
The severity level of CVE-2018-16876 is medium with a CVSS score of 5.3.
What is the affected software for CVE-2018-16876?
The affected software for CVE-2018-16876 includes Ansible versions 2.5.14, 2.6.11, and 2.7.5.
How can I fix CVE-2018-16876?
To fix CVE-2018-16876, update Ansible to version 2.5.14, 2.6.11, or 2.7.5.
Where can I find more information about CVE-2018-16876?
You can find more information about CVE-2018-16876 at the following references: [GitHub](https://github.com/ansible/ansible/pull/49569), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16876), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2018:3835).