CVE-2019-14846

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/10/2019
Last modified:
22/04/2022

Description

In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:* 2.6.20 (excluding)
cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:* 2.7.0 (including) 2.7.14 (excluding)
cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:* 2.8.0 (including) 2.8.6 (excluding)
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_engine:2.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_engine:2.8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:8.0:*:*:*:*:*:*:*