CVE-2019-10217
published 2019-11-25CVE-2019-10217: A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.85%
76.9th percentile
A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for all gcp modules is not setting no_log to True. Any sensitive data managed by that function would be leak as an output when running ansible playbooks.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 2.8.6+dfsg-1 (bookworm) | ansible 2.8.6+dfsg-1 (bookworm) |
| red_hat | ansible | — | — |
| redhat | ansible | >= 0 < 2.8.6+dfsg-1 | 2.8.6+dfsg-1 |
| redhat | ansible | >= 0 < 2.8.6+dfsg-1 | 2.8.6+dfsg-1 |
| redhat | ansible | >= 0 < 2.8.6+dfsg-1 | 2.8.6+dfsg-1 |
| redhat | ansible | >= 0 < 2.8.6+dfsg-1 | 2.8.6+dfsg-1 |
| redhat | ansible | >= 2.8.0 < 2.8.4 | 2.8.4 |
| redhat | ansible | >= 2.8.0a1 < 2.8.4 | 2.8.4 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.05.7MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in ansible
ghsa·2021-10-12
CVE-2019-10217 [HIGH] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in ansible
Exposure of Sensitive Information to an Unauthorized Actor in ansible
A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for all gcp modules is not setting no_log to True. Any sensitive data managed by that function would be leak as an output when running ansible playbooks.
OSV
Exposure of Sensitive Information to an Unauthorized Actor in ansible
osv·2021-10-12
CVE-2019-10217 [HIGH] Exposure of Sensitive Information to an Unauthorized Actor in ansible
Exposure of Sensitive Information to an Unauthorized Actor in ansible
A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for all gcp modules is not setting no_log to True. Any sensitive data managed by that function would be leak as an output when running ansible playbooks.
OSV
CVE-2019-10217: A flaw was found in ansible 2
osv·2019-11-25·CVSS 6.5
CVE-2019-10217 [MEDIUM] CVE-2019-10217: A flaw was found in ansible 2
A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for all gcp modules is not setting no_log to True. Any sensitive data managed by that function would be leak as an output when running ansible playbooks.
Red Hat
Ansible: gcp modules do not flag sensitive data fields properly
vendor_redhat·2019-07-26·CVSS 6.5
CVE-2019-10217 [MEDIUM] CWE-200 Ansible: gcp modules do not flag sensitive data fields properly
Ansible: gcp modules do not flag sensitive data fields properly
A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for all gcp modules is not setting no_log to True. Any sensitive data managed by that function would be leak as an output when running ansible playbooks.
A flaw was found in the gcp module of ansible. Certain fields managing sensitive data should be marked by the no_log feature. The service_account_contents(), which is common class for all gcp modules, is not being set as no_log to True. Any sensitive data managed by that function would be leaked as an output when running ansible playbooks. Data confid
Debian
CVE-2019-10217: ansible - A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data s...
vendor_debian·2019·CVSS 6.5
CVE-2019-10217 [MEDIUM] CVE-2019-10217: ansible - A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data s...
A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for all gcp modules is not setting no_log to True. Any sensitive data managed by that function would be leak as an output when running ansible playbooks.
Scope: local
bookworm: resolved (fixed in 2.8.6+dfsg-1)
bullseye: resolved (fixed in 2.8.6+dfsg-1)
forky: resolved (fixed in 2.8.6+dfsg-1)
sid: resolved (fixed in 2.8.6+dfsg-1)
trixie: resolved (fixed in 2.8.6+dfsg-1)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10217https://github.com/ansible/ansible/issues/56269https://github.com/ansible/ansible/pull/59427http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10217https://github.com/ansible/ansible/issues/56269https://github.com/ansible/ansible/pull/59427
2019-11-25
Published