ansible: Information disclosure in vvv+ mode with no_log on
Published Jan 3, 2019
8.2
HIGHCVSS 4.0
EPSS 2.48%
Description
ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.
Affected products
-
- Version before 2.5.14StatusaffectedConstraints-
- Version before 2.6.11StatusaffectedConstraints-
- Version before 2.7.5StatusaffectedConstraints-
- Version
Configuration 1
Configuration 2
- 9.0
Configuration 3
- 2.0
- 2.5
- 2.6
- 2.7
- 14
- 7.0
- 7.0
- 7.0
Configuration 4
- n/a
Running on/with
- 12.0
Configuration 5
- 16.04
- 18.04
- 19.04
No data.
Red Hat Ansible Engine 2 for RHEL 7
ansible-0:2.7.5-1.el7ae
Fixed · RHSA-2018:3838
Red Hat Ansible Engine 2.5 for RHEL 7
ansible-0:2.5.14-1.el7ae
Fixed · RHSA-2018:3835
Red Hat Ansible Engine 2.6 for RHEL 7
ansible-0:2.6.11-1.el7ae
Fixed · RHSA-2018:3836
Red Hat Ansible Engine 2.7 for RHEL 7
ansible-0:2.7.5-1.el7ae
Fixed · RHSA-2018:3837
Red Hat OpenStack Platform 13.0 (Queens)
ansible-0:2.6.11-1.el7ae
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
openstack-ec2-api-0:6.0.1-0.20181123223255.1e25260.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
openstack-manila-1:6.0.2-5.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
openstack-selinux-0:0.8.17-2.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
openstack-tempest-1:18.0.0-6.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
os-apply-config-0:8.3.1-0.20180831234255.be699ba.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
python-barbicanclient-0:4.6.0-2.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
python-docker-0:2.4.2-2.el7
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
python-heat-tests-tempest-0:0.1.1-0.20180514163845.9d99219.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
python-novajoin-0:1.0.22-1.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
python-openstackclient-0:3.14.3-2.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
python-openstacksdk-0:0.11.3-2.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
python-vmware-nsxlib-0:12.0.4-3.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 13.0 (Queens)
rhosp-release-0:13.0.5-1.el7ost
Fixed · RHSA-2019:0564
Red Hat OpenStack Platform 14.0 (Rocky)
ansible-0:2.6.11-1.el7ae
Fixed · RHSA-2019:0590
CloudForms Management Engine 5
ansible
Not affected
Red Hat Ansible Tower 3
ansible
Not affected
Red Hat Ceph Storage 2
ansible
Affected
Red Hat Ceph Storage 3
ansible
Will not fix
Red Hat OpenShift Container Platform 3.2
ansible
Will not fix
Red Hat OpenShift Container Platform 3.3
ansible
Will not fix
Red Hat OpenShift Container Platform 3.4
ansible
Will not fix
Red Hat OpenShift Container Platform 3.5
ansible
Will not fix
Red Hat OpenShift Container Platform 3.6
ansible
Will not fix
Red Hat OpenShift Container Platform 3.7
ansible
Will not fix
Red Hat OpenStack Platform 10 (Newton)
ansible
Will not fix
Red Hat Satellite 6
ansible
Out of support scope
Red Hat Storage 3
ansible
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Engine 2 for RHEL 7 | ansible-0:2.7.5-1.el7ae | Fixed | RHSA-2018:3838 |
| Red Hat Ansible Engine 2.5 for RHEL 7 | ansible-0:2.5.14-1.el7ae | Fixed | RHSA-2018:3835 |
| Red Hat Ansible Engine 2.6 for RHEL 7 | ansible-0:2.6.11-1.el7ae | Fixed | RHSA-2018:3836 |
| Red Hat Ansible Engine 2.7 for RHEL 7 | ansible-0:2.7.5-1.el7ae | Fixed | RHSA-2018:3837 |
| Red Hat OpenStack Platform 13.0 (Queens) | ansible-0:2.6.11-1.el7ae | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | openstack-ec2-api-0:6.0.1-0.20181123223255.1e25260.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | openstack-manila-1:6.0.2-5.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | openstack-selinux-0:0.8.17-2.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | openstack-tempest-1:18.0.0-6.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | os-apply-config-0:8.3.1-0.20180831234255.be699ba.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | python-barbicanclient-0:4.6.0-2.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | python-docker-0:2.4.2-2.el7 | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | python-heat-tests-tempest-0:0.1.1-0.20180514163845.9d99219.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | python-novajoin-0:1.0.22-1.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | python-openstackclient-0:3.14.3-2.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | python-openstacksdk-0:0.11.3-2.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | python-vmware-nsxlib-0:12.0.4-3.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 13.0 (Queens) | rhosp-release-0:13.0.5-1.el7ost | Fixed | RHSA-2019:0564 |
| Red Hat OpenStack Platform 14.0 (Rocky) | ansible-0:2.6.11-1.el7ae | Fixed | RHSA-2019:0590 |
| CloudForms Management Engine 5 | ansible | Not affected | n/a |
| Red Hat Ansible Tower 3 | ansible | Not affected | n/a |
| Red Hat Ceph Storage 2 | ansible | Affected | n/a |
| Red Hat Ceph Storage 3 | ansible | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.2 | ansible | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.3 | ansible | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.4 | ansible | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.5 | ansible | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.6 | ansible | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.7 | ansible | Will not fix | n/a |
| Red Hat OpenStack Platform 10 (Newton) | ansible | Will not fix | n/a |
| Red Hat Satellite 6 | ansible | Out of support scope | n/a |
| Red Hat Storage 3 | ansible | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
AV:N/AC:M/Au:S/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 2.48% (0.02483) | 84.05th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.46% (0.02462) | 82.31th | v5 (v2026.06.15) |
| Mar 30, 2025 | 0.95% (0.00951) | 74.31th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.49% (0.02487) | 75.49th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.28% (0.01281) | 78.21th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.32% (0.00319) | 71.36th | v3 (v2023.03.01) |
| May 26, 2024 | 0.22% (0.00224) | 60.67th | v3 (v2023.03.01) |
| May 18, 2024 | 0.25% (0.00249) | 64.75th | v3 (v2023.03.01) |
| Dec 28, 2023 | 0.25% (0.00249) | 62.73th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.20% (0.00202) | 56.33th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
| Feb 3, 2022 | 3.08% (0.03080) | 65.20th | v5 (v2026.06.15) |
| Apr 14, 2021 | 3.08% (0.03080) | 0.00th | v1 |
References (25)
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00021.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00077.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00020.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://www.securityfocus.com/bid/106225 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:3835 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3836 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3837 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3838 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0564 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0590 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2018-16876 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1657330 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16876 x_refsource_CONFIRMIssue TrackingPatchVendor Advisory
- https://github.com/advisories/GHSA-j569-fghw-f9rx Advisory
- https://github.com/ansible/ansible/commit/0954942dfdc563f80fd3e388f550aa165ec931da
- https://github.com/ansible/ansible/commit/424c68f15ad9f532d73e5afed33ff477f54281a7
- https://github.com/ansible/ansible/commit/e0a81d133ffc8f7067182c53cf6a28c724dd1099
- https://github.com/ansible/ansible/issues/51318
- https://github.com/ansible/ansible/pull/49569 x_refsource_MISCPatchThird Party Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2019-141.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2018-16876
- https://usn.ubuntu.com/4072-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://web.archive.org/web/20200227100904/http://www.securityfocus.com/bid/106225
- https://www.cve.org/CVERecord?id=CVE-2018-16876
- https://www.debian.org/security/2019/dsa-4396 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.