CVE-2025-14010
published 2025-12-04CVE-2025-14010: A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically…
PriorityP427medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.12%
2.1th percentile
A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-collections | ansible_community_general_collection | >= 10.0.0 < 10.7.6 | 10.7.6 |
| ansible-collections | ansible_community_general_collection | >= 11.0.0 < 11.4.1 | 11.4.1 |
| ansible-collections | ansible_community_general_collection | >= 12.0.0 < 12.2.0 | 12.2.0 |
| ansible-collections | ansible_community_general_collection | >= 7.1.0 < 9.5.13 | 9.5.13 |
| debian | ansible | < ansible 12.2.0+dfsg-1 (forky) | ansible 12.2.0+dfsg-1 (forky) |
| redhat | ansible | >= 0 < 12.0.0+dfsg-0+deb13u1 | 12.0.0+dfsg-0+deb13u1 |
| redhat | ansible | >= 0 < 12.2.0+dfsg-1 | 12.2.0+dfsg-1 |
| redhat | ansible | >= 0 < 12.2.0 | 12.2.0 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Ansible Community General Collection is vulnerable to exposure of sensitive information
osv·2025-12-04
CVE-2025-14010 [MEDIUM] Ansible Community General Collection is vulnerable to exposure of sensitive information
Ansible Community General Collection is vulnerable to exposure of sensitive information
A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.
GHSA
Ansible Community General Collection is vulnerable to exposure of sensitive information
ghsa·2025-12-04
CVE-2025-14010 [MEDIUM] CWE-200 Ansible Community General Collection is vulnerable to exposure of sensitive information
Ansible Community General Collection is vulnerable to exposure of sensitive information
A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.
OSV
CVE-2025-14010: A flaw was found in ansible-collection-community-general
osv·2025-12-04·CVSS 5.5
CVE-2025-14010 [MEDIUM] CVE-2025-14010: A flaw was found in ansible-collection-community-general
A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.
Red Hat
ansible-collection-community-general: ansible-collection-community-general: Keycloak user module leaks credentials in verbose output
vendor_redhat·2025-12-04·CVSS 5.5
CVE-2025-14010 [MEDIUM] ansible-collection-community-general: ansible-collection-community-general: Keycloak user module leaks credentials in verbose output
ansible-collection-community-general: ansible-collection-community-general: Keycloak user module leaks credentials in verbose output
A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.
A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentia
Debian
CVE-2025-14010: ansible - A flaw was found in ansible-collection-community-general. This vulnerability all...
vendor_debian·2025·CVSS 5.5
CVE-2025-14010 [MEDIUM] CVE-2025-14010: ansible - A flaw was found in ansible-collection-community-general. This vulnerability all...
A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 12.2.0+dfsg-1)
sid: resolved (fixed in 12.2.0+dfsg-1)
trixie: resolved (fixed in 12.0.0+dfsg-0+deb13u1)
No detection rules found.
No public exploits indexed.
https://access.redhat.com/security/cve/CVE-2025-14010https://bugzilla.redhat.com/show_bug.cgi?id=2418774https://github.com/ansible-collections/community.general/issues/11000https://github.com/ansible-collections/community.general/pull/11005https://github.com/ansible-community/ansible-build-data/blob/main/12/CHANGELOG-v12.md#security-fixeshttps://github.com/ansible-collections/community.general/issues/11000
2025-12-04
Published