CVE-2016-8647

unknown
Published 2018-10-10 · Modified 2023-11-08
CVSS v3
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CVSS v2
VIR risk

Description

An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2016-8647.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-8647

OS impact

OSVersionStatusFixed in
debian debianforkyfixed2.2.0.0-4
debian debianbookwormfixed2.2.0.0-4
debian debiansidfixed2.2.0.0-4
debian debiantrixiefixed2.2.0.0-4
debian debianbullseyefixed2.2.0.0-4
suse slesaffected

Package impact

EcosystemPackageVulnerableFixed
python PyPIansible<2.2.1.02.2.1.0

References

Verify integrity in audit chain (admin only). AS-IS.