CVE-2019-14864
published 2020-01-02CVE-2019-14864: Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when…
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.86%
76.8th percentile
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 2.9.2+dfsg-1 (bookworm) | ansible 2.9.2+dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| redhat | ansible | >= 0 < 2.9.2+dfsg-1 | 2.9.2+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.2+dfsg-1 | 2.9.2+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.2+dfsg-1 | 2.9.2+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.2+dfsg-1 | 2.9.2+dfsg-1 |
| redhat | ansible | >= 2.7.0 < 2.7.15 | 2.7.15 |
| redhat | ansible | >= 2.7.0a1 < 2.7.15 | 2.7.15 |
| redhat | ansible | >= 2.8.0 < 2.8.7 | 2.8.7 |
| redhat | ansible | >= 2.8.0a1 < 2.8.7 | 2.8.7 |
| redhat | ansible | >= 2.9.0 < 2.9.1 | 2.9.1 |
| redhat | ansible | >= 2.9.0a1 < 2.9.1 | 2.9.1 |
| redhat | ansible_tower | — | — |
| redhat | ceph_storage | — | — |
| redhat | cloudforms_management_engine | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.05.7MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Ansible: Splunk and Sumologic callback plugins leak sensitive data in logs
vendor_redhat·2019-10-22·CVSS 6.5
CVE-2019-14864 [MEDIUM] CWE-213 Ansible: Splunk and Sumologic callback plugins leak sensitive data in logs
Ansible: Splunk and Sumologic callback plugins leak sensitive data in logs
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
A data disclosure flaw was found in Ansible when using the Splunk and Sumologic modules, as they are not respecting when the flag no_log is enabled. This flaw can disclose and collect sensitive data from the system and expose it to an attacker.
Statement: * The exploitation of this flaw depends on the use of either Sumo Logic or Splunk callback plugins. However, because Red Hat OpenStack Platform (RHOSP) does not use Sumo L
Debian
CVE-2019-14864: ansible - Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2....
vendor_debian·2019·CVSS 6.5
CVE-2019-14864 [MEDIUM] CVE-2019-14864: ansible - Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2....
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
Scope: local
bookworm: resolved (fixed in 2.9.2+dfsg-1)
bullseye: resolved (fixed in 2.9.2+dfsg-1)
forky: resolved (fixed in 2.9.2+dfsg-1)
sid: resolved (fixed in 2.9.2+dfsg-1)
trixie: resolved (fixed in 2.9.2+dfsg-1)
GHSA
Inclusion of Sensitive Information in Log Files and Improper Output Neutralization for Logs in Ansible
ghsa·2020-02-26
CVE-2019-14864 [MEDIUM] CWE-532 Inclusion of Sensitive Information in Log Files and Improper Output Neutralization for Logs in Ansible
Inclusion of Sensitive Information in Log Files and Improper Output Neutralization for Logs in Ansible
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
OSV
Inclusion of Sensitive Information in Log Files and Improper Output Neutralization for Logs in Ansible
osv·2020-02-26
CVE-2019-14864 [MEDIUM] Inclusion of Sensitive Information in Log Files and Improper Output Neutralization for Logs in Ansible
Inclusion of Sensitive Information in Log Files and Improper Output Neutralization for Logs in Ansible
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
OSV
CVE-2019-14864: Ansible, versions 2
osv·2020-01-02·CVSS 6.5
CVE-2019-14864 [MEDIUM] CVE-2019-14864: Ansible, versions 2
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14864 ansible: Splunk and Sumologic callback plugins leak sensitive data in logs [epel-6]
bugzilla·2019-11-19·CVSS 6.5
CVE-2019-14864 [MEDIUM] CVE-2019-14864 ansible: Splunk and Sumologic callback plugins leak sensitive data in logs [epel-6]
CVE-2019-14864 ansible: Splunk and Sumologic callback plugins leak sensitive data in logs [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following temp
Bugzilla
CVE-2019-14864 ansible: Splunk and Sumologic callback plugins leak sensitive data in logs [openstack-rdo]
bugzilla·2019-11-19·CVSS 6.5
CVE-2019-14864 [MEDIUM] CVE-2019-14864 ansible: Splunk and Sumologic callback plugins leak sensitive data in logs [openstack-rdo]
CVE-2019-14864 ansible: Splunk and Sumologic callback plugins leak sensitive data in logs [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Fixed by
Bugzilla
CVE-2019-14864 ansible: Splunk and Sumologic callback plugins leak sensitive data in logs [epel-7]
bugzilla·2019-11-19·CVSS 6.5
CVE-2019-14864 [MEDIUM] CVE-2019-14864 ansible: Splunk and Sumologic callback plugins leak sensitive data in logs [epel-7]
CVE-2019-14864 ansible: Splunk and Sumologic callback plugins leak sensitive data in logs [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following temp
Bugzilla
CVE-2019-14864 ansible: Splunk and Sumologic callback plugins leak sensitive data in logs [fedora-all]
bugzilla·2019-11-19·CVSS 6.5
CVE-2019-14864 [MEDIUM] CVE-2019-14864 ansible: Splunk and Sumologic callback plugins leak sensitive data in logs [fedora-all]
CVE-2019-14864 ansible: Splunk and Sumologic callback plugins leak sensitive data in logs [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mu
Bugzilla
CVE-2019-14864 Ansible: Splunk and Sumologic callback plugins leak sensitive data in logs
bugzilla·2019-10-22·CVSS 6.5
CVE-2019-14864 [MEDIUM] CVE-2019-14864 Ansible: Splunk and Sumologic callback plugins leak sensitive data in logs
CVE-2019-14864 Ansible: Splunk and Sumologic callback plugins leak sensitive data in logs
Ansible is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
Discussion:
Upstream issue: https://github.com/ansible/ansible/issues/63522
Upstream fix: https://github.com/ansible/ansible/pull/63527
---
Acknowledgments:
Name: Abhijeet Kasurde (Red Hat), Patrick O’Brien (The Trade Desk Inc)
---
Created ansible tracking bugs for this issue:
Affects: epel-6 [bug 1774003]
Affects: epel-7 [bug 1774004]
Affects: fedora-all [bug 1774005]
Affects: openstack-rdo [bug 1774007]
---
This issue has been addressed in the following products:
Red Hat Ansible Engine 2
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14864https://github.com/ansible/ansible/issues/63522https://github.com/ansible/ansible/pull/63527https://www.debian.org/security/2021/dsa-4950http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14864https://github.com/ansible/ansible/issues/63522https://github.com/ansible/ansible/pull/63527https://www.debian.org/security/2021/dsa-4950
2020-01-02
Published