CVE-2018-16876: Information Exposure
(updated )
ansible is vulnerable to an information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.
References
- www.securityfocus.com/bid/106225
- access.redhat.com/errata/RHSA-2018:3835
- access.redhat.com/errata/RHSA-2018:3836
- access.redhat.com/errata/RHSA-2018:3837
- access.redhat.com/errata/RHSA-2018:3838
- access.redhat.com/errata/RHSA-2019:0564
- access.redhat.com/errata/RHSA-2019:0590
- bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16876
- cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16876
- cwe.mitre.org/data/definitions/200.html
- github.com/ansible/ansible/pull/49569
- www.debian.org/security/2019/dsa-4396
Detect and mitigate CVE-2018-16876 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →