In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.

Project Subscriptions

Vendors Products
Debian Linux Subscribe
Opensuse Subscribe
Backports Sle Subscribe
Ansible Engine Subscribe
Enterprise Linux Server Subscribe
Openstack Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2202-1 ansible security update
Debian DLA Debian DLA DLA-2535-1 ansible security update
Debian DSA Debian DSA DSA-4950-1 ansible security update
EUVD EUVD EUVD-2019-0008 In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.
Github GHSA Github GHSA GHSA-pm48-cvv2-29q5 Ansible Uses Plugins That Disclose Credentials
Ubuntu USN Ubuntu USN USN-7330-1 Ansible vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-05T00:26:39.176Z

Reserved: 2019-08-10T00:00:00

Link: CVE-2019-14846

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-10-08T19:15:10.400

Modified: 2024-11-21T04:27:29.307

Link: CVE-2019-14846

cve-icon Redhat

Severity : Important

Publid Date: 2019-10-08T00:00:00Z

Links: CVE-2019-14846 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses