Back

MEDIUM

ansible: become password logged in plaintext when used with PowerShell on Windows

Published Nov 29, 2018

Description

Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. Ansible Engine 2.8 and older are believed to be vulnerable.

Affected products

Remediation

Red Hat statement

CloudForms and Satellite 6 are not affected by this issue, since Microsoft Windows is not a supported platform.

Metrics

Weaknesses (1)

References (21)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 29, 2018
Updated Aug 5, 2024
Reserved Sep 11, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 16, 2018
GHSA-V735-2PP6-H86R