Ansible: Information leak in "user" module
Published Oct 23, 2018
8.5
HIGHCVSS 4.0
EPSS 0.36%
Description
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.
Affected products
- Vendor n/a Product Ansible Defaultn/a
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| n/a | Ansible | n/a |
|
Configuration 1
- 2.0
- 2.5
- 2.6
- 2.7
- 3.3.0
Configuration 2
- 8.0
- 9.0
Configuration 3
- n/a
Running on/with
- 12.0
No data.
Red Hat Ansible Engine 2 for RHEL 7
ansible-0:2.7.1-1.el7ae
Fixed · RHSA-2018:3462
Red Hat Ansible Engine 2.5 for RHEL 7
ansible-0:2.5.11-1.el7ae
Fixed · RHSA-2018:3461
Red Hat Ansible Engine 2.6 for RHEL 7
ansible-0:2.6.7-1.el7ae
Fixed · RHSA-2018:3460
Red Hat Ansible Engine 2.7 for RHEL 7
ansible-0:2.7.1-1.el7ae
Fixed · RHSA-2018:3463
Red Hat OpenStack Platform 13.0 (Queens)
ansible-0:2.6.11-1.el7ae
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
openstack-ec2-api-0:6.0.1-0.20181123223255.1e25260.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
openstack-manila-1:6.0.2-5.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
openstack-selinux-0:0.8.17-2.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
openstack-tempest-1:18.0.0-6.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
os-apply-config-0:8.3.1-0.20180831234255.be699ba.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
python-barbicanclient-0:4.6.0-2.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
python-docker-0:2.4.2-2.el7
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
python-heat-tests-tempest-0:0.1.1-0.20180514163845.9d99219.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
python-novajoin-0:1.0.22-1.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
python-openstackclient-0:3.14.3-2.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
python-openstacksdk-0:0.11.3-2.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
python-vmware-nsxlib-0:12.0.4-3.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
rhosp-release-0:13.0.5-1.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 14.0 (Rocky)
ansible-0:2.6.11-1.el7ae
Fixed · RHSA-2019:0590
Red Hat Ceph Storage 2
ansible
Out of support scope
Red Hat Ceph Storage 3
ansible
Will not fix
Red Hat OpenStack Platform 10 (Newton)
ansible
Will not fix
Red Hat Storage 3
ansible
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Engine 2 for RHEL 7 | ansible-0:2.7.1-1.el7ae | Fixed | RHSA-2018:3462 |
| Red Hat Ansible Engine 2.5 for RHEL 7 | ansible-0:2.5.11-1.el7ae | Fixed | RHSA-2018:3461 |
| Red Hat Ansible Engine 2.6 for RHEL 7 | ansible-0:2.6.7-1.el7ae | Fixed | RHSA-2018:3460 |
| Red Hat Ansible Engine 2.7 for RHEL 7 | ansible-0:2.7.1-1.el7ae | Fixed | RHSA-2018:3463 |
| Red Hat OpenStack Platform 13.0 (Queens) | ansible-0:2.6.11-1.el7ae | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | openstack-ec2-api-0:6.0.1-0.20181123223255.1e25260.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | openstack-manila-1:6.0.2-5.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | openstack-selinux-0:0.8.17-2.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | openstack-tempest-1:18.0.0-6.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | os-apply-config-0:8.3.1-0.20180831234255.be699ba.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | python-barbicanclient-0:4.6.0-2.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | python-docker-0:2.4.2-2.el7 | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | python-heat-tests-tempest-0:0.1.1-0.20180514163845.9d99219.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | python-novajoin-0:1.0.22-1.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | python-openstackclient-0:3.14.3-2.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | python-openstacksdk-0:0.11.3-2.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | python-vmware-nsxlib-0:12.0.4-3.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | rhosp-release-0:13.0.5-1.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 14.0 (Rocky) | ansible-0:2.6.11-1.el7ae | Fixed | RHSA-2019:0590 |
| Red Hat Ceph Storage 2 | ansible | Out of support scope | n/a |
| Red Hat Ceph Storage 3 | ansible | Will not fix | n/a |
| Red Hat OpenStack Platform 10 (Newton) | ansible | Will not fix | n/a |
| Red Hat Storage 3 | ansible | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the version of ansible as shipped with Red Hat Ceph Storage 3, as it contains the vulnerable code which leaks the data when ssh-keygen is invoked with any arguments.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.36% (0.00365) | 27.98th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.35% (0.00354) | 27.04th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.03% (0.00027) | 4.68th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.06% (0.00064) | 30.08th | v3 (v2023.03.01) |
| Oct 17, 2023 | 0.06% (0.00064) | 26.71th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00046) | 14.04th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.88% (0.02880) | 63.65th | v1 |
| Jan 6, 2022 | 2.88% (0.02880) | 63.31th | v1 |
| Sep 1, 2021 | 2.88% (0.02880) | 80.71th | v1 |
| Apr 14, 2021 | 2.88% (0.02880) | 0.00th | v1 |
References (29)
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00021.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00077.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00020.html vendor-advisoryx_refsource_SUSE
- http://www.securityfocus.com/bid/105700 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:3460 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3461 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3462 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3463 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3505 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2018-16837 Vendor Advisory
- https://access.redhat.com/security/cve/cve-2018-16837 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1640642 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16837 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://github.com/advisories/GHSA-hwrm-63v2-42g4 Advisory
- https://github.com/ansible/ansible/blob/c963ef1dfbf73efea5106624eb48b346f01eaefd/changelogs/CHANGELOG-v2.7.rst?plain=1#L138
- https://github.com/ansible/ansible/commit/77928e6c3a2ad878b20312ce5d74d9d7741e0df0
- https://github.com/ansible/ansible/commit/b618339c321c387230d3ea523e80ad47af3de5cf
- https://github.com/ansible/ansible/commit/f50cc0b8cb399bb7b7c1ad23b94c9404f0cc6d23
- https://github.com/ansible/ansible/pull/47436
- https://github.com/ansible/ansible/pull/47445
- https://github.com/ansible/ansible/pull/47486
- https://github.com/ansible/ansible/pull/47487
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2018-44.yaml
- https://lists.debian.org/debian-lts-announce/2018/11/msg00012.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-16837
- https://usn.ubuntu.com/4072-1 vendor-advisoryx_refsource_UBUNTU
- https://web.archive.org/web/20200227105539/http://www.securityfocus.com/bid/105700
- https://www.cve.org/CVERecord?id=CVE-2018-16837
- https://www.debian.org/security/2019/dsa-4396 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.