CVE-2018-10855
Last modified
CVE-2018-10855 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.. EPSS estimates a 3.09% chance of exploitation in the next 30 days.
Description
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Ansible Engine | >= 2.4, < 2.4.5 |
| Redhat | Ansible Engine | > 2.5, <= 2.5.5 |
| Redhat | Ansible Engine | 2.0 |
| Redhat | Cloudforms | 4.6 |
| Redhat | Openstack | 13 |
| Redhat | Virtualization | 4.0 |
| Debian | Debian Linux | 9.0 |
| Redhat | Openstack | 10 |
| Redhat | Openstack | 12 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 19.04 |
References
- https://access.redhat.com/errata/RHBA-2018:3788Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1948Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1949Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2022Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2079Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2184Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2585Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0054Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10855Issue Tracking, Vendor Advisory
- https://usn.ubuntu.com/4072-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4396Third Party Advisory
- https://access.redhat.com/errata/RHBA-2018:3788Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1948Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1949Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2022Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2079Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2184Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2585Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0054Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10855Issue Tracking, Vendor Advisory
- https://usn.ubuntu.com/4072-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4396Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10855?
How severe is CVE-2018-10855?
How do I fix CVE-2018-10855?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-1085openshift-ansible before versions 3.9.23, 3.7.46 deploys a m…9
- CVE-2018-10850389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable …5.9
- CVE-2018-10851PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.…5.3
- CVE-2018-10852The UNIX pipe which sudo uses to contact SSSD and read the a…3.8
- CVE-2018-10853A flaw was found in the way Linux kernel KVM hypervisor befo…7
- CVE-2018-10854cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vu…5.4
- CVE-2018-10856It has been discovered that podman before version 0.6.1 does…5.3
- CVE-2018-10857git-annex is vulnerable to a private data exposure and exfil…5.9
- CVE-2018-10858A heap-buffer overflow was found in the way samba clients pr…4.3
- CVE-2018-10859git-annex is vulnerable to an Information Exposure when decr…5.9
- CVE-2018-1086pcs before versions 0.9.164 and 0.10 is vulnerable to a debu…4.3
- CVE-2018-10860perl-archive-zip is vulnerable to a directory traversal in A…5.4
Are you affected by CVE-2018-10855?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
