Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2018-07-02T18:00:00

Updated: 2024-08-05T07:46:47.397Z

Reserved: 2018-05-09T00:00:00

Link: CVE-2018-10855

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-07-03T01:29:00.580

Modified: 2021-08-04T17:14:46.777

Link: CVE-2018-10855

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-06-11T00:00:00Z

Links: CVE-2018-10855 - Bugzilla