Ansible Logs Passwords If PowerShell ScriptBlock is Enabled
Moderate severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Sep 4, 2024
Package
Affected versions
>= 2.7.0a1, < 2.7.3
>= 0, < 2.5.12
>= 2.6.0a1, < 2.6.9
Patched versions
2.7.3
2.5.12
2.6.9
Description
Published by the National Vulnerability Database
Nov 29, 2018
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Apr 22, 2024
Last updated
Sep 4, 2024
Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. Ansible Engine 2.8 and older are believed to be vulnerable.
References