Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| ansible(PyPI) | 2.7.0a1 | 2.7.1 | N/A |
| ansible(PyPI) | 2.6.0a1 | 2.6.7 | N/A |
| ansible(PyPI) | 0 | 2.5.11 | N/A |
CVSS Metrics