cbcvebase.
CVE-2019-14858
published 2019-10-14

CVE-2019-14858: A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as…

PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.43%
34.6th percentile
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields will not be masked and will be displayed if Ansible is run with increased verbosity and present in the module invocation arguments for the task.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianansible< ansible 2.8.6+dfsg-1 (bookworm)ansible 2.8.6+dfsg-1 (bookworm)
red_hatansible
red_hatansible
redhatansible>= 0 < 2.8.6+dfsg-12.8.6+dfsg-1
redhatansible>= 0 < 2.8.6+dfsg-12.8.6+dfsg-1
redhatansible>= 0 < 2.8.6+dfsg-12.8.6+dfsg-1
redhatansible>= 0 < 2.8.6+dfsg-12.8.6+dfsg-1
redhatansible>= 2.0 < 2.6.202.6.20
redhatansible>= 2.7.0a1 < 2.7.142.7.14
redhatansible>= 2.8.0a1 < 2.8.62.8.6
redhatansible>= 2.9.0a1 < 2.9.0rc42.9.0rc4
redhatansible_engine2.0 – 2.8.0
redhatansible_tower3.0 – 3.5.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.07.3HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.