CVE-2018-16837: Debian Linux

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Red Hat Ansible Engine: version 2.0 only; version 2.5 only; version 2.6 only; version 2.7 only
  • Red Hat Ansible Tower: version 3.3.0 only
  • Suse Package Hub: affected versions not specified

Published 2018-10-23. Last modified 2026-06-17.