3.5
CVSSv2

CVE-2018-16876

Published: 03/01/2019 Updated: 04/08/2021
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.3 | Impact Score: 3.6 | Exploitability Score: 1.6
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

ansible prior to 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat ansible

debian debian linux 9.0

redhat ansible engine 2.0

redhat ansible engine 2.5

redhat ansible engine 2.7

redhat enterprise linux desktop 7.0

redhat enterprise linux server 7.0

redhat enterprise linux workstation 7.0

redhat ansible engine 2.6

redhat openstack 14

suse package_hub -

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 19.04

Vendor Advisories

Debian Bug report logs - #916102 ansible: CVE-2018-16876: Information disclosure in vvv+ mode with no_log on Package: src:ansible; Maintainer for src:ansible is Harlan Lieberman-Berg <hlieberman@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 10 Dec 2018 08:15:06 UTC Severity: serious Ta ...
Several security issues were fixed in Ansible ...
Several vulnerabilities have been found in Ansible, a configuration management, deployment, and task execution system: CVE-2018-10855 / CVE-2018-16876 The no_log task flag wasn't honored, resulting in an information leak CVE-2018-10875 ansiblecfg was read from the current working directory CVE-2018-16837 The user module leaked param ...
Synopsis Low: ansible security and bug fix update Type/Severity Security Advisory: Low Topic An update for ansible is now available for Ansible Engine 27Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives a ...
Synopsis Low: Red Hat Enterprise Linux OpenStack Platform security update Type/Severity Security Advisory: Low Topic An update is now available for Red Hat OpenStack Platform 130 (Queens)Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring Syste ...
Synopsis Low: ansible security and bug fix update Type/Severity Security Advisory: Low Topic An update for ansible is now available for Ansible Engine 26Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives a ...
Synopsis Low: ansible security and bug fix update Type/Severity Security Advisory: Low Topic An update for ansible is now available for Ansible Engine 25Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives a ...
Synopsis Low: ansible security and bug fix update Type/Severity Security Advisory: Low Topic An update for ansible is now available for Red Hat OpenStack Platform 140 (Rocky)Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base ...
Synopsis Low: ansible security and bug fix update Type/Severity Security Advisory: Low Topic An update for ansible is now available for Ansible Engine 2Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives a d ...
ansible before versions 2514, 2611, 275 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data ...