cbcvebase.
CVE-2025-14010
published 2025-12-04

CVE-2025-14010: A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically…

PriorityP427medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.12%
2.1th percentile
A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.

Affected

8 ranges
VendorProductVersion rangeFixed in
ansible-collectionsansible_community_general_collection>= 10.0.0 < 10.7.610.7.6
ansible-collectionsansible_community_general_collection>= 11.0.0 < 11.4.111.4.1
ansible-collectionsansible_community_general_collection>= 12.0.0 < 12.2.012.2.0
ansible-collectionsansible_community_general_collection>= 7.1.0 < 9.5.139.5.13
debianansible< ansible 12.2.0+dfsg-1 (forky)ansible 12.2.0+dfsg-1 (forky)
redhatansible>= 0 < 12.0.0+dfsg-0+deb13u112.0.0+dfsg-0+deb13u1
redhatansible>= 0 < 12.2.0+dfsg-112.2.0+dfsg-1
redhatansible>= 0 < 12.2.012.2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.