GHSA-6fq2-x65v-v9h7

    Dashboard / Vulnerabilities / GHSA-6fq2-x65v-v9h7

    GHSA-6fq2-x65v-v9h7

    Published: 24 May 2022Last Modified: 24 Nov 2024

    Summary: Ansible password prompts could expose passwords

    Details: A data disclosure flaw was found in ansible. Password prompts in ansible-playbook and ansible-cli tools could expose passwords with special characters as they are not properly wrapped. A password with special characters is exposed starting with the first of these special characters. The highest threat from this vulnerability is to data confidentiality. This CVE exists due to an incomplete fix for CVE-2019-10206.

    Affected packages

    Package

    Name: ansible

    Purl: pkg:pypi/ansible

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 2.8.0
    Fixed -2.8.6

    Affected versions

    2.8.0
    2.8.1
    2.8.2
    2.8.3
    2.8.4
    2.8.5

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-6fq2-x65v-v9h7 | CVE-DB