CVE-2018-16876: Canonical Ubuntu Linux
Medium severity, CVSS 5.3. EPSS: 2.5% chance of exploitation in the next 30 days.
ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only
- Debian Debian Linux: version 9.0 only
- Red Hat Ansible: from 2.5.0, before 2.5.14 (fixed in 2.5.14); from 2.6.0, before 2.6.11 (fixed in 2.6.11); from 2.7.0, before 2.7.5 (fixed in 2.7.5)
- Red Hat Ansible Engine: version 2.0 only; version 2.5 only; version 2.6 only; version 2.7 only
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
- Red Hat Openstack: version 14 only
- Suse Package Hub: affected versions not specified
Published 2019-01-03. Last modified 2026-06-17.