Debian Security Advisory
DLA-1576-1 ansible -- LTS security update
- Date Reported:
- 12 Nov 2018
- Affected Packages:
- Security database references:
- In Mitre's CVE dictionary: CVE-2018-16837.
- More information:
It was discovered that there was a potential SSH passphrase disclosure vulnerability in the ansible configuration management system,
Usermodule leaked data that was passed as a parameter to the ssh-keygen(1) utility, thus revealing any credentials in cleartext form in the global process list.
For Debian 8
Jessie, this issue has been fixed in ansible version 1.7.2+dfsg-2+deb8u1.
We recommend that you upgrade your ansible packages.