cbcvebase.
CVE-2019-14864
published 2020-01-02

CVE-2019-14864: Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when…

PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.86%
76.8th percentile
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianansible< ansible 2.9.2+dfsg-1 (bookworm)ansible 2.9.2+dfsg-1 (bookworm)
debiandebian_linux
opensusebackports_sle
opensuseleap
red_hatansible
red_hatansible
red_hatansible
redhatansible>= 0 < 2.9.2+dfsg-12.9.2+dfsg-1
redhatansible>= 0 < 2.9.2+dfsg-12.9.2+dfsg-1
redhatansible>= 0 < 2.9.2+dfsg-12.9.2+dfsg-1
redhatansible>= 0 < 2.9.2+dfsg-12.9.2+dfsg-1
redhatansible>= 2.7.0 < 2.7.152.7.15
redhatansible>= 2.7.0a1 < 2.7.152.7.15
redhatansible>= 2.8.0 < 2.8.72.8.7
redhatansible>= 2.8.0a1 < 2.8.72.8.7
redhatansible>= 2.9.0 < 2.9.12.9.1
redhatansible>= 2.9.0a1 < 2.9.12.9.1
redhatansible_tower
redhatceph_storage
redhatcloudforms_management_engine
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.05.7MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.