cbcvebase.
CVE-2019-14864
published 2020-01-02

CVE-2019-14864: Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when…

medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianansible< ansible 2.9.2+dfsg-1 (bookworm)ansible 2.9.2+dfsg-1 (bookworm)
debiandebian_linux
opensusebackports_sle
opensuseleap
red_hatansible
red_hatansible
red_hatansible
redhatansible>= 0 < 2.9.2+dfsg-12.9.2+dfsg-1
redhatansible>= 0 < 2.9.2+dfsg-12.9.2+dfsg-1
redhatansible>= 0 < 2.9.2+dfsg-12.9.2+dfsg-1
redhatansible>= 0 < 2.9.2+dfsg-12.9.2+dfsg-1
redhatansible>= 2.7.0 < 2.7.152.7.15
redhatansible>= 2.7.0a1 < 2.7.152.7.15
redhatansible>= 2.8.0 < 2.8.72.8.7
redhatansible>= 2.8.0a1 < 2.8.72.8.7
redhatansible>= 2.9.0 < 2.9.12.9.1
redhatansible>= 2.9.0a1 < 2.9.12.9.1
redhatansible_tower
redhatceph_storage
redhatcloudforms_management_engine
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv6.5MEDIUM