Debian Security Advisory
DLA-1576-1 ansible -- LTS security update
- Date Reported:
- 12 Nov 2018
- Affected Packages:
- ansible
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2018-16837.
- More information:
-
It was discovered that there was a potential SSH passphrase disclosure vulnerability in the ansible configuration management system,
The
User
module leaked data that was passed as a parameter to the ssh-keygen(1) utility, thus revealing any credentials in cleartext form in the global process list.For Debian 8
Jessie
, this issue has been fixed in ansible version 1.7.2+dfsg-2+deb8u1.We recommend that you upgrade your ansible packages.