5.9
CVE-2018-10855
- EPSS 3.11%
- Veröffentlicht 03.07.2018 01:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:08
- Erkennungen
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Ansible Engine Version >= 2.4 < 2.4.5
Redhat ≫ Ansible Engine Version > 2.5 <= 2.5.5
Redhat ≫ Ansible Engine Version 2.0
Redhat ≫ Cloudforms Version 4.6
Redhat ≫ Virtualization Version 4.0
Debian ≫ Debian Linux Version 9.0
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.04
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.11% | 0.865 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
| RedHat | 5.9 | 2.2 | 3.6 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.
https://access.redhat.com/errata/RHBA-2018:3788
https://access.redhat.com/errata/RHSA-2018:2585
https://access.redhat.com/errata/RHSA-2019:0054
https://usn.ubuntu.com/4072-1/
https://access.redhat.com/errata/RHSA-2018:1948
https://access.redhat.com/errata/RHSA-2018:1949
https://access.redhat.com/errata/RHSA-2018:2022
https://access.redhat.com/errata/RHSA-2018:2079
https://access.redhat.com/errata/RHSA-2018:2184
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10855
https://www.debian.org/security/2019/dsa-4396