CVE-2018-10855Log File Information Exposure in Redhat Ansible Engine

Severity
5.9MEDIUMNVD
OSV9.8
EPSS
3.4%
top 12.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 3
Latest updateJul 24

Description

Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages7 packages

PyPIredhat/ansible2.5.0a12.5.5+1
NVDredhat/ansible_engine2.42.4.5+2
Debianredhat/ansible< 2.5.5+dfsg-1+3
Ubunturedhat/ansible< 2.0.0.2-2ubuntu1.3+1
NVDredhat/openstack10, 12, 13+2

Also affects: Debian Linux 9.0, Ubuntu Linux 16.04, 18.04, 19.04

🔴Vulnerability Details

5
OSV
ansible vulnerabilities2019-07-24
OSV
Ansible exposes sensitive data in log files and on the terminal2018-10-10
GHSA
Ansible exposes sensitive data in log files and on the terminal2018-10-10
OSV
CVE-2018-10855: Ansible 22018-07-03
CVEList
CVE-2018-10855: Ansible 22018-07-02

📋Vendor Advisories

3
Ubuntu
Ansible vulnerabilities2019-07-24
Red Hat
ansible: Failed tasks do not honour no_log option allowing for secrets to be disclosed in logs2018-06-11
Debian
CVE-2018-10855: ansible - Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task...2018

💬Community

3
Bugzilla
CVE-2018-10855 ansible: Failed tasks do not honour no_log option allowing for secrets to be disclosed in logs [fedora-all]2018-06-12
Bugzilla
CVE-2018-10855 ansible: Failed tasks do not honour no_log option allowing for secrets to be disclosed in logs [epel-all]2018-06-12
Bugzilla
CVE-2018-10855 ansible: Failed tasks do not honour no_log option allowing for secrets to be disclosed in logs2018-06-08
CVE-2018-10855 — Log File Information Exposure | cvebase