{"id":"CVE-2018-16859","aliases":["GHSA-v735-2pp6-h86r","PYSEC-2018-60"],"url":"https://o3.security/vulnerability/CVE-2018-16859","summary":"Ansible Logs Passwords If PowerShell ScriptBlock is Enabled","details":"Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. Ansible Engine 2.8 and older are believed to be vulnerable.","published":"2018-11-29T18:29:00.537Z","modified":"2026-08-07T14:58:37.121679Z","cvss":{"score":4.4,"severity":"MEDIUM","vector":"CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"ansible","fixedVersion":"2.7.3"},{"ecosystem":"PyPI","name":"ansible","fixedVersion":"2.5.12"},{"ecosystem":"PyPI","name":"ansible","fixedVersion":"2.6.9"}],"fix":{"url":"https://github.com/ansible/ansible/pull/49142","label":"ansible/ansible#49142"},"references":[{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00021.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00077.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00020.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/106004"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:3770"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:3771"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:3773"},{"type":"REPORT","url":"https://access.redhat.com/errata/RHSA-2018:3772"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16859"},{"type":"FIX","url":"https://github.com/ansible/ansible/pull/49142"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:58:37.121679Z"}}