CVE-2016-8647

An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:virtualization:4.1:*:*:*:*:*:*:*

History

12 Feb 2023, 23:26

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2016-8647', 'name': 'https://access.redhat.com/security/cve/CVE-2016-8647', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1396174', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1396174', 'tags': [], 'refsource': 'MISC'}
Summary An input validation vulnerability was found in Ansible's mysql_user module which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed. An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed.

02 Feb 2023, 16:17

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2016-8647 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1396174 -
Summary An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed. An input validation vulnerability was found in Ansible's mysql_user module which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed.

Information

Published : 2018-07-26 14:29

Updated : 2024-01-26 18:02


NVD link : CVE-2016-8647

Mitre link : CVE-2016-8647

CVE.ORG link : CVE-2016-8647


JSON object : View

Products Affected

redhat

  • virtualization
  • ansible_engine
CWE
CWE-20

Improper Input Validation