Lucene search

K
osvGoogleOSV:GHSA-HWRM-63V2-42G4
HistoryMay 13, 2022 - 1:50 a.m.

Ansible Leaks Data Passed to ssh-keygen

2022-05-1301:50:27
Google
osv.dev
6

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.1%

Ansible “User” module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.

References

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.1%