{
  "threat_severity" : "Moderate",
  "public_date" : "2018-10-23T06:46:00Z",
  "bugzilla" : {
    "description" : "Ansible: Information leak in \"user\" module",
    "id" : "1640642",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1640642"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.8",
    "cvss3_scoring_vector" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-214",
  "details" : [ "Ansible \"User\" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.", "The User module in Ansible leaks any data which is passed on as a parameter to ssh-keygen. This could lead to undesirable situations such as passphrase credentials being passed as a parameter for the ssh-keygen executable, showing those credentials in clear text form for every user which have access just to the process list." ],
  "statement" : "This issue affects the version of ansible as shipped with Red Hat Ceph Storage 3, as it contains the vulnerable code which leaks the data when ssh-keygen is invoked with any arguments.",
  "acknowledgement" : "Red Hat would like to thank Markus Teufelberger (mgIT Consulting) for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat Ansible Engine 2.5 for RHEL 7",
    "release_date" : "2018-11-05T00:00:00Z",
    "advisory" : "RHSA-2018:3461",
    "cpe" : "cpe:/a:redhat:ansible_engine:2.5::el7",
    "package" : "ansible-0:2.5.11-1.el7ae",
    "impact" : "moderate"
  }, {
    "product_name" : "Red Hat Ansible Engine 2.6 for RHEL 7",
    "release_date" : "2018-11-05T00:00:00Z",
    "advisory" : "RHSA-2018:3460",
    "cpe" : "cpe:/a:redhat:ansible_engine:2.6::el7",
    "package" : "ansible-0:2.6.7-1.el7ae",
    "impact" : "moderate"
  }, {
    "product_name" : "Red Hat Ansible Engine 2.7 for RHEL 7",
    "release_date" : "2018-11-05T00:00:00Z",
    "advisory" : "RHSA-2018:3463",
    "cpe" : "cpe:/a:redhat:ansible_engine:2.7::el7",
    "package" : "ansible-0:2.7.1-1.el7ae",
    "impact" : "moderate"
  }, {
    "product_name" : "Red Hat Ansible Engine 2 for RHEL 7",
    "release_date" : "2018-11-05T00:00:00Z",
    "advisory" : "RHSA-2018:3462",
    "cpe" : "cpe:/a:redhat:ansible_engine:2::el7",
    "package" : "ansible-0:2.7.1-1.el7ae",
    "impact" : "moderate"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2019-03-14T00:00:00Z",
    "advisory" : "RHSA-2019:0564",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "ansible-0:2.6.11-1.el7ae"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2019-03-14T00:00:00Z",
    "advisory" : "RHSA-2019:0564",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "openstack-ec2-api-0:6.0.1-0.20181123223255.1e25260.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2019-03-14T00:00:00Z",
    "advisory" : "RHSA-2019:0564",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "openstack-manila-1:6.0.2-5.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2019-03-14T00:00:00Z",
    "advisory" : "RHSA-2019:0564",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "openstack-selinux-0:0.8.17-2.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2019-03-14T00:00:00Z",
    "advisory" : "RHSA-2019:0564",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "openstack-tempest-1:18.0.0-6.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2019-03-14T00:00:00Z",
    "advisory" : "RHSA-2019:0564",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "os-apply-config-0:8.3.1-0.20180831234255.be699ba.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2019-03-14T00:00:00Z",
    "advisory" : "RHSA-2019:0564",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-barbicanclient-0:4.6.0-2.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2019-03-14T00:00:00Z",
    "advisory" : "RHSA-2019:0564",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-docker-0:2.4.2-2.el7"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2019-03-14T00:00:00Z",
    "advisory" : "RHSA-2019:0564",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-heat-tests-tempest-0:0.1.1-0.20180514163845.9d99219.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2019-03-14T00:00:00Z",
    "advisory" : "RHSA-2019:0564",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-novajoin-0:1.0.22-1.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2019-03-14T00:00:00Z",
    "advisory" : "RHSA-2019:0564",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-openstackclient-0:3.14.3-2.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2019-03-14T00:00:00Z",
    "advisory" : "RHSA-2019:0564",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-openstacksdk-0:0.11.3-2.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2019-03-14T00:00:00Z",
    "advisory" : "RHSA-2019:0564",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-vmware-nsxlib-0:12.0.4-3.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2019-03-14T00:00:00Z",
    "advisory" : "RHSA-2019:0564",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "rhosp-release-0:13.0.5-1.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 14.0 (Rocky)",
    "release_date" : "2019-03-18T00:00:00Z",
    "advisory" : "RHSA-2019:0590",
    "cpe" : "cpe:/a:redhat:openstack:14::el7",
    "package" : "ansible-0:2.6.11-1.el7ae"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Ceph Storage 2",
    "fix_state" : "Out of support scope",
    "package_name" : "ansible",
    "cpe" : "cpe:/a:redhat:ceph_storage:2"
  }, {
    "product_name" : "Red Hat Ceph Storage 3",
    "fix_state" : "Will not fix",
    "package_name" : "ansible",
    "cpe" : "cpe:/a:redhat:ceph_storage:3"
  }, {
    "product_name" : "Red Hat OpenStack Platform 10 (Newton)",
    "fix_state" : "Will not fix",
    "package_name" : "ansible",
    "cpe" : "cpe:/a:redhat:openstack:10"
  }, {
    "product_name" : "Red Hat Storage 3",
    "fix_state" : "Will not fix",
    "package_name" : "ansible",
    "cpe" : "cpe:/a:redhat:storage:3"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2018-16837\nhttps://nvd.nist.gov/vuln/detail/CVE-2018-16837\nhttps://github.com/ansible/ansible/pull/47436" ],
  "name" : "CVE-2018-16837",
  "csaw" : false
}