Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13131
HistoryJan 15, 2019 - 9:26 a.m.

Information Disclosure

2019-01-1509:26:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.001 Low

EPSS

Percentile

28.1%

ansible is vulnerable to information disclosure. The vulnerability exists in the user module when it passes the ssh_key_passphrase value to the ssh-keygen executable as a parameter, allowing any user with access to the process list to retrieve the passphrase in cleartext.