CVE-2018-16859
Last modified
CVE-2018-16859 is a vulnerability of currently unknown severity. Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. Ansible Engine 2.8 and older are believed to be vulnerable.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Ansible Engine | < 2.5.13 |
| Redhat | Ansible Engine | >= 2.6.0, < 2.6.10 |
| Redhat | Ansible Engine | >= 2.7.0, < 2.7.4 |
| Redhat | Ansible Engine | >= 2.7.5, <= 2.8 |
References
- http://www.securityfocus.com/bid/106004Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3770Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3771Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3772Issue Tracking, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3773Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16859Issue Tracking, Vendor Advisory
- https://github.com/ansible/ansible/pull/49142Patch, Third Party Advisory
- http://www.securityfocus.com/bid/106004Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3770Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3771Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3772Issue Tracking, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3773Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16859Issue Tracking, Vendor Advisory
- https://github.com/ansible/ansible/pull/49142Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-16859?
How severe is CVE-2018-16859?
How do I fix CVE-2018-16859?
Are you affected by CVE-2018-16859?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
