cbcvebase.
CVE-2019-10217
published 2019-11-25

CVE-2019-10217: A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are…

PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.85%
76.9th percentile
A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for all gcp modules is not setting no_log to True. Any sensitive data managed by that function would be leak as an output when running ansible playbooks.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianansible< ansible 2.8.6+dfsg-1 (bookworm)ansible 2.8.6+dfsg-1 (bookworm)
red_hatansible
redhatansible>= 0 < 2.8.6+dfsg-12.8.6+dfsg-1
redhatansible>= 0 < 2.8.6+dfsg-12.8.6+dfsg-1
redhatansible>= 0 < 2.8.6+dfsg-12.8.6+dfsg-1
redhatansible>= 0 < 2.8.6+dfsg-12.8.6+dfsg-1
redhatansible>= 2.8.0 < 2.8.42.8.4
redhatansible>= 2.8.0a1 < 2.8.42.8.4

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.05.7MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.