Vulnerability Description
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Ansible Engine | < 2.6.20 |
| Debian | Debian Linux | 8.0 |
| Opensuse | Backports Sle | 15.0 |
| Opensuse | Leap | 15.1 |
| Redhat | Openstack | 13 |
| Redhat | Enterprise Linux Server | 7.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.htmlMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3201Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:3202Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:3203Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:3207Vendor Advisory
- https://access.redhat.com/errata/RHSA-2020:0756Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14846Issue TrackingVendor Advisory
- https://github.com/ansible/ansible/pull/63366PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/05/msg00005.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/01/msg00023.htmlMailing ListThird Party Advisory
- https://www.debian.org/security/2021/dsa-4950Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.htmlMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3201Vendor Advisory
FAQ
What is CVE-2019-14846?
CVE-2019-14846 is a vulnerability with a CVSS score of 7.8 (HIGH). In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin ...
How severe is CVE-2019-14846?
CVE-2019-14846 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-14846?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Ansible Engine, Debian Debian Linux, Opensuse Backports Sle, Opensuse Leap, Redhat Openstack.