ansible: become password logged in plaintext when used with PowerShell on Windows
Published Nov 29, 2018
6.7
MEDIUMCVSS 4.0
EPSS 0.54%
Description
Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. Ansible Engine 2.8 and older are believed to be vulnerable.
Affected products
-
- Version 2.8 and olderStatusaffectedConstraints-
- Version
- < 2.5.13
- ≥ 2.6.0 · < 2.6.10
- ≥ 2.7.0 · < 2.7.4
- ≥ 2.7.5 · ≤ 2.8
No data.
Red Hat Ansible Engine 2 for RHEL 7
ansible-0:2.7.4-1.el7ae
Fixed · RHSA-2018:3772
Red Hat Ansible Engine 2.5 for RHEL 7
ansible-0:2.5.13-1.el7ae
Fixed · RHSA-2018:3770
Red Hat Ansible Engine 2.6 for RHEL 7
ansible-0:2.6.10-1.el7ae
Fixed · RHSA-2018:3771
Red Hat Ansible Engine 2.7 for RHEL 7
ansible-0:2.7.4-1.el7ae
Fixed · RHSA-2018:3773
CloudForms Management Engine 5
ansible
Not affected
Red Hat Ceph Storage 2
ansible
Will not fix
Red Hat Ceph Storage 3
ansible
Affected
Red Hat OpenShift Container Platform 3.2
ansible
Not affected
Red Hat OpenShift Container Platform 3.3
ansible
Not affected
Red Hat OpenShift Container Platform 3.4
ansible
Will not fix
Red Hat OpenShift Container Platform 3.5
ansible
Will not fix
Red Hat OpenShift Container Platform 3.6
ansible
Will not fix
Red Hat OpenShift Container Platform 3.7
ansible
Affected
Red Hat OpenShift Enterprise 3.0
ansible
Not affected
Red Hat OpenShift Enterprise 3.1
ansible
Not affected
Red Hat OpenStack Platform 10 (Newton)
ansible
Will not fix
Red Hat OpenStack Platform 12 (Pike)
ansible
Will not fix
Red Hat OpenStack Platform 13 (Queens)
ansible
Will not fix
Red Hat OpenStack Platform 14 (Rocky)
ansible
Will not fix
Red Hat Satellite 6
ansible
Not affected
Red Hat Storage 3
ansible
Will not fix
Red Hat Virtualization 4
ansible
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Engine 2 for RHEL 7 | ansible-0:2.7.4-1.el7ae | Fixed | RHSA-2018:3772 |
| Red Hat Ansible Engine 2.5 for RHEL 7 | ansible-0:2.5.13-1.el7ae | Fixed | RHSA-2018:3770 |
| Red Hat Ansible Engine 2.6 for RHEL 7 | ansible-0:2.6.10-1.el7ae | Fixed | RHSA-2018:3771 |
| Red Hat Ansible Engine 2.7 for RHEL 7 | ansible-0:2.7.4-1.el7ae | Fixed | RHSA-2018:3773 |
| CloudForms Management Engine 5 | ansible | Not affected | n/a |
| Red Hat Ceph Storage 2 | ansible | Will not fix | n/a |
| Red Hat Ceph Storage 3 | ansible | Affected | n/a |
| Red Hat OpenShift Container Platform 3.2 | ansible | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.3 | ansible | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.4 | ansible | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.5 | ansible | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.6 | ansible | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.7 | ansible | Affected | n/a |
| Red Hat OpenShift Enterprise 3.0 | ansible | Not affected | n/a |
| Red Hat OpenShift Enterprise 3.1 | ansible | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | ansible | Will not fix | n/a |
| Red Hat OpenStack Platform 12 (Pike) | ansible | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | ansible | Will not fix | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | ansible | Will not fix | n/a |
| Red Hat Satellite 6 | ansible | Not affected | n/a |
| Red Hat Storage 3 | ansible | Will not fix | n/a |
| Red Hat Virtualization 4 | ansible | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
CloudForms and Satellite 6 are not affected by this issue, since Microsoft Windows is not a supported platform.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
1 other source (Red Hat) ▾
CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
AV:L/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.54% (0.00539) | 43.36th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.53% (0.00535) | 40.66th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.10% (0.00101) | 25.58th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 5.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.86% (0.01864) | 77.24th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.86% (0.01864) | 77.19th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.86% (0.01864) | 75.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.86% (0.01864) | 54.47th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.13% (0.02129) | 50.49th | v1 |
| Jan 6, 2022 | 2.13% (0.02129) | 49.99th | v1 |
| Sep 1, 2021 | 2.13% (0.02129) | 77.33th | v1 |
| Apr 14, 2021 | 2.13% (0.02129) | 0.00th | v1 |
References (21)
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00021.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00077.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00020.html vendor-advisoryx_refsource_SUSE
- http://www.securityfocus.com/bid/106004 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:3770 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3771 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3772 vendor-advisoryx_refsource_REDHATIssue TrackingVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3773 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2018-16859 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1649607 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16859 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://github.com/advisories/GHSA-v735-2pp6-h86r Advisory
- https://github.com/ansible/ansible/blob/v2.5.13/changelogs/CHANGELOG-v2.5.rst
- https://github.com/ansible/ansible/commit/0d746b4198abf84290a093b83cf02b4203d73d9f
- https://github.com/ansible/ansible/commit/2f8d3fcf41107efafc14d51ab6e14531ca8f8c87
- https://github.com/ansible/ansible/commit/4d748d34f9392aa469da00a85c8e2d5fe6cec52b
- https://github.com/ansible/ansible/pull/49142 x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2018-60.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2018-16859
- https://web.archive.org/web/20200227102121/http://www.securityfocus.com/bid/106004
- https://www.cve.org/CVERecord?id=CVE-2018-16859
Change history (0)
No recorded changes yet.