suse · CVE-2018-16837

Quick triage

Priority: high Published: 2021-05-30 14:16:46 UTC Updated: 2026-04-17 15:17:08 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-16837 severity important: SUSE including 120 source package names (ansible-10-10.6.0-1.1, ansible-11-11.11.0-1.1, …), 251 product×package rows across 13 product lines (HPE Helion OpenStack 8, SUSE Linux Enterprise Server 11 SP3-TERADATA, … (13 product lines)): Fixed 251.

Description:

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.

cvelogic Threat Intelligence