Ansible Leaks Data Passed to ssh-keygen
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Sep 4, 2024
Package
Affected versions
>= 2.7.0a1, < 2.7.1
>= 2.6.0a1, < 2.6.7
>= 0, < 2.5.11
Patched versions
2.7.1
2.6.7
2.5.11
Description
Published by the National Vulnerability Database
Oct 23, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Apr 22, 2024
Last updated
Sep 4, 2024
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.
References