Vulnerability Name:

CVE-2018-16859 (CCN-153604)

Assigned:2018-11-27
Published:2018-11-27
Updated:2019-04-03
Summary:Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. Ansible Engine 2.8 and older are believed to be vulnerable.
CVSS v3 Severity:4.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
3.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): High
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
2.3 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N)
2.0 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): High
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
1.7 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-532
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2018-16859

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2019:1125

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2019:1635

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2019:1858

Source: BID
Type: Third Party Advisory, VDB Entry
106004

Source: REDHAT
Type: Vendor Advisory
RHSA-2018:3770

Source: REDHAT
Type: Vendor Advisory
RHSA-2018:3771

Source: REDHAT
Type: Issue Tracking, Vendor Advisory
RHSA-2018:3772

Source: REDHAT
Type: Vendor Advisory
RHSA-2018:3773

Source: CONFIRM
Type: Issue Tracking, Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16859

Source: XF
Type: UNKNOWN
ansible-cve201816859-info-disc(153604)

Source: CCN
Type: ansible GIT Repository
split PS wrapper and payload #49142

Source: CONFIRM
Type: Patch, Third Party Advisory
https://github.com/ansible/ansible/pull/49142

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2018-16859

Vulnerable Configuration:Configuration 1:
  • cpe:/a:redhat:ansible_engine:*:*:*:*:*:*:*:* (Version < 2.5.13)
  • OR cpe:/a:redhat:ansible_engine:*:*:*:*:*:*:*:* (Version >= 2.6.0 and < 2.6.10)
  • OR cpe:/a:redhat:ansible_engine:*:*:*:*:*:*:*:* (Version >= 2.7.0 and < 2.7.4)
  • OR cpe:/a:redhat:ansible_engine:*:*:*:*:*:*:*:* (Version >= 2.7.5 and <= 2.8)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201816859
    V
    CVE-2018-16859
    2022-06-30
    oval:org.opensuse.security:def:111931
    P
    ansible-2.9.24-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:93429
    P
    (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:105499
    P
    ansible-2.9.24-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:60340
    P
    Security update for openssl-1_1 (Important)
    2021-08-24
    oval:org.opensuse.security:def:63374
    P
    sca-patterns-sle12-1.0.2-1.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63010
    P
    go1.16-1.16.3-1.11.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62808
    P
    libpotrace0-1.15-3.19 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62329
    P
    squashfs-4.4-1.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62328
    P
    spectre-meltdown-checker-0.43-3.3.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62352
    P
    xalan-j2-2.7.2-9.64 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:59856
    P
    Security update for python-cryptography (Important)
    2021-03-02
    oval:org.opensuse.security:def:60456
    P
    Security update for tomcat (Moderate)
    2021-02-19
    oval:org.opensuse.security:def:60300
    P
    Security update for postgresql, postgresql12, postgresql13 (Important)
    2021-01-26
    oval:org.opensuse.security:def:61058
    P
    Security update for openexr (Moderate)
    2020-12-23
    oval:org.opensuse.security:def:62529
    P
    gvim-8.0.1568-3.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63148
    P
    dovecot23-2.3.1-2.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:60111
    P
    Security update for the Linux Kernel (Live Patch 30 for SLE 12 SP2) (Important)
    2020-12-01
    oval:org.opensuse.security:def:60761
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:25715
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25003
    P
    Security update for mariadb-100 (Important)
    2020-12-01
    oval:org.opensuse.security:def:60815
    P
    Security update for python3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63835
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60041
    P
    Security update for bash (Important)
    2020-12-01
    oval:org.opensuse.security:def:26403
    P
    Security update for ffmpeg (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25326
    P
    Security update for libvirt (Important)
    2020-12-01
    oval:org.opensuse.security:def:64197
    P
    ruby2.5-rubygem-actionview-5_1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60634
    P
    Security update for openssl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60718
    P
    Security update for python3-requests (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25566
    P
    Security update for openexr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26432
    P
    Security update for ansible (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:61028
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:25269
    P
    Security update for libpng12 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25721
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:64043
    P
    Security update for SUSE Manager Client Tools (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25613
    P
    Security update for libsolv (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60711
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:25332
    P
    Security update for sane-backends (Important)
    2020-12-01
    oval:org.opensuse.security:def:25759
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25188
    P
    Security update for texlive (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60899
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63941
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26438
    P
    Security update for ansible (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25410
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:74137
    P
    Security update for graphviz (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25275
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:60672
    P
    Security update for python-PyKMIP (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25061
    P
    Security update for libseccomp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25701
    P
    Security update for libexif (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24986
    P
    Security update for cronie (Low)
    2020-12-01
    oval:org.opensuse.security:def:25619
    P
    Security update for libmspack (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63701
    P
    Security update for java-1_7_0-openjdk (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60978
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:25765
    P
    Security update for Adobe Flash Player (Important)
    2020-12-01
    oval:org.opensuse.security:def:25194
    P
    Security update for adns (Important)
    2020-12-01
    oval:org.opensuse.security:def:64085
    P
    Security update for freetype2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:24997
    P
    Security update for evince (Important)
    2020-12-01
    oval:org.opensuse.security:def:60552
    P
    sysvinit-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60600
    P
    Security update for postgresql10 (Important)
    2020-12-01
    oval:org.opensuse.security:def:60790
    P
    Security update for ansible, ardana-ansible, ardana-cinder, ardana-glance, ardana-mq, ardana-nova, ardana-osconfig, crowbar-core, crowbar-openstack, documentation-suse-openstack-cloud, grafana, grafana-natel-discrete-panel, openstack-cinder, openstack-monasca-installer, openstack-neutron, openstack-nova, python-Django, python-Flask-Cors, python-Pillow, python-ardana-packager, python-keystoneclient, python-keystonemiddleware, python-kombu, python-straight-plugin, python-urllib3, release-notes-suse-openstack-cloud, storm, storm-kit, venv-openstack-cinder, venv-openstack-swift (Important)
    2020-12-01
    oval:org.opensuse.security:def:25416
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26397
    P
    Security update for plasma5-workspace (Important)
    2020-12-01
    oval:org.opensuse.security:def:60937
    P
    Security update for galera-3, mariadb, mariadb-connector-c (Important)
    2020-12-01
    oval:org.opensuse.security:def:25067
    P
    Security update for libjpeg-turbo (Important)
    2020-12-01
    oval:org.opensuse.security:def:25707
    P
    Security update for java-1_7_1-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24992
    P
    Security update for polkit (Important)
    2020-12-01
    oval:org.opensuse.security:def:25560
    P
    Security update for openldap2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:74263
    P
    Security update for ansible (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:84056
    P
    Security update for ansible, ardana-ansible, ardana-cinder, ardana-glance, ardana-mq, ardana-nova, ardana-osconfig, crowbar-core, crowbar-openstack, documentation-suse-openstack-cloud, grafana, grafana-natel-discrete-panel, openstack-cinder, openstack-monasca-installer, openstack-neutron, openstack-nova, python-Django, python-Flask-Cors, python-Pillow, python-ardana-packager, python-keystoneclient, python-keystonemiddleware, python-kombu, python-straight-plugin, python-urllib3, release-notes-suse-openstack-cloud, storm, storm-kit, venv-openstack-cinder, venv-openstack-swift (Important)
    2020-11-12
    oval:org.opensuse.security:def:84511
    P
    Security update for ansible, ardana-ansible, ardana-cinder, ardana-glance, ardana-mq, ardana-nova, ardana-osconfig, crowbar-core, crowbar-openstack, documentation-suse-openstack-cloud, grafana, grafana-natel-discrete-panel, openstack-cinder, openstack-monasca-installer, openstack-neutron, openstack-nova, python-Django, python-Flask-Cors, python-Pillow, python-ardana-packager, python-keystoneclient, python-keystonemiddleware, python-kombu, python-straight-plugin, python-urllib3, release-notes-suse-openstack-cloud, storm, storm-kit, venv-openstack-cinder, venv-openstack-swift (Important)
    2020-11-12
    oval:org.opensuse.security:def:100142
    P
    Security update for ansible (Moderate)
    2019-08-13
    oval:org.opensuse.security:def:109887
    P
    Security update for ansible (Moderate)
    2019-06-27
    BACK
    redhat ansible engine *
    redhat ansible engine *
    redhat ansible engine *
    redhat ansible engine *