3.5
CVSSv2

CVE-2018-16876

Published: 03/01/2019 Updated: 29/05/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.3 | Impact Score: 3.6 | Exploitability Score: 1.6
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

ansible prior to 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

suse package_hub -

Vendor Advisories

Synopsis Low: ansible security and bug fix update Type/Severity Security Advisory: Low Topic An update for ansible is now available for Ansible Engine 2Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives a d ...
Synopsis Low: ansible security and bug fix update Type/Severity Security Advisory: Low Topic An update for ansible is now available for Ansible Engine 25Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives a ...
Synopsis Low: ansible security and bug fix update Type/Severity Security Advisory: Low Topic An update for ansible is now available for Ansible Engine 26Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives a ...
Synopsis Low: ansible security and bug fix update Type/Severity Security Advisory: Low Topic An update for ansible is now available for Red Hat OpenStack Platform 140 (Rocky)Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base ...
Synopsis Low: ansible security and bug fix update Type/Severity Security Advisory: Low Topic An update for ansible is now available for Ansible Engine 27Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives a ...
Synopsis Low: Red Hat Enterprise Linux OpenStack Platform security update Type/Severity Security Advisory: Low Topic An update is now available for Red Hat OpenStack Platform 130 (Queens)Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring Syste ...
Debian Bug report logs - #916102 ansible: CVE-2018-16876: Information disclosure in vvv+ mode with no_log on Package: src:ansible; Maintainer for src:ansible is Harlan Lieberman-Berg <hlieberman@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 10 Dec 2018 08:15:06 UTC Severity: serious Ta ...
ansible before versions 2514, 2611, 275 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data ...
Several vulnerabilities have been found in Ansible, a configuration management, deployment, and task execution system: CVE-2018-10855 / CVE-2018-16876 The no_log task flag wasn't honored, resulting in an information leak CVE-2018-10875 ansiblecfg was read from the current working directory CVE-2018-16837 The user module leaked param ...
Several security issues were fixed in Ansible ...

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4396-1 security () debian org wwwdebianorg/security/ Moritz Muehlenhoff February 19, 2019 wwwdebianorg/security/faq ...