ZeroHour

CVE-2018-16876

CVSS 3.1
5.3 medium
EPSS
2%p84
Published
()
Modified
Description

ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.

Vendors
redhatdebiansusecanonical
Products
ansible, debian linux, ansible engine, openstack, enterprise linux desktop, enterprise linux server, enterprise linux workstation, package hub, ubuntu linux
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.