CVE-2018-16859
MEDIUM4.4EPSS 0.09%Ansible Logs Passwords If PowerShell ScriptBlock is Enabled
發布日:2022/5/14修改日:2025/11/19
描述
Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. Ansible Engine 2.8 and older are believed to be vulnerable.
受影響套件(3)
- Alpine/ansiblefrom 0, < 2.7.3-r0
- PyPI/ansible>= 2.7.0a1, < 2.7.3
- PyPI/ansible>= 2.7.0, < 2.7.4, >= 2.7.5, < 2.8.1, from 0, < 2.5.13, >= 2.6.0, < 2.6.10
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | MEDIUM4.4 | CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
參考連結(19)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2018-16859
- ADVISORYhttps://security.alpinelinux.org/vuln/CVE-2018-16859
- PATCHhttps://github.com/ansible/ansible
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00021.html
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00077.html
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00020.html
- WEBhttps://access.redhat.com/errata/RHSA-2018:3770
- WEBhttps://access.redhat.com/errata/RHSA-2018:3771
- WEBhttps://access.redhat.com/errata/RHSA-2018:3772
- WEBhttps://access.redhat.com/errata/RHSA-2018:3773
- WEBhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16859
- WEBhttps://github.com/ansible/ansible/blob/v2.5.13/changelogs/CHANGELOG-v2.5.rst
- WEBhttps://github.com/ansible/ansible/commit/0d746b4198abf84290a093b83cf02b4203d73d9f
- WEBhttps://github.com/ansible/ansible/commit/2f8d3fcf41107efafc14d51ab6e14531ca8f8c87
- WEBhttps://github.com/ansible/ansible/commit/4d748d34f9392aa469da00a85c8e2d5fe6cec52b
- WEBhttps://github.com/ansible/ansible/pull/49142
- WEBhttps://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2018-60.yaml
- WEBhttps://web.archive.org/web/20200227102121/http://www.securityfocus.com/bid/106004
- WEBhttp://www.securityfocus.com/bid/106004