A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8ggh-xwr9-3373 Ansible Community General Collection is vulnerable to exposure of sensitive information
Fixes

Solution

No solution given by the vendor.


Workaround

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

History

Fri, 05 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 04 Dec 2025 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 04 Dec 2025 10:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.
Title Ansible-collection-community-general: ansible-collection-community-general: keycloak user module leaks credentials in verbose output
First Time appeared Redhat
Redhat ceph Storage
Redhat openstack
CPEs cpe:/a:redhat:ceph_storage:5
cpe:/a:redhat:ceph_storage:6
cpe:/a:redhat:ceph_storage:7
cpe:/a:redhat:ceph_storage:8
cpe:/a:redhat:openstack:17.1
cpe:/a:redhat:openstack:18.0
Vendors & Products Redhat
Redhat ceph Storage
Redhat openstack
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-12-05T17:23:00.707Z

Reserved: 2025-12-04T09:30:09.669Z

Link: CVE-2025-14010

cve-icon Vulnrichment

Updated: 2025-12-05T17:22:56.623Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-04T10:16:00.810

Modified: 2025-12-04T17:15:08.283

Link: CVE-2025-14010

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-12-04T00:00:00Z

Links: CVE-2025-14010 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses

No weakness.