CVE-2018-10855

MEDIUMCVSS 5.9/10EPSS 3.09%

Last modified

CVE-2018-10855 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.. EPSS estimates a 3.09% chance of exploitation in the next 30 days.

Description

Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.

Metrics

CVSS 3.1
5.9/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
3.09%

86.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
RedhatAnsible Engine>= 2.4, < 2.4.5
RedhatAnsible Engine> 2.5, <= 2.5.5
RedhatAnsible Engine2.0
RedhatCloudforms4.6
RedhatOpenstack13
RedhatVirtualization4.0
DebianDebian Linux9.0
RedhatOpenstack10
RedhatOpenstack12
CanonicalUbuntu Linux16.04
CanonicalUbuntu Linux18.04
CanonicalUbuntu Linux19.04

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-10855?
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.
How severe is CVE-2018-10855?
CVE-2018-10855 has a CVSS score of 5.9/10 (MEDIUM severity). The EPSS model estimates a 3.09% probability of exploitation in the next 30 days.
How do I fix CVE-2018-10855?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-10855?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST