Vulnerability Description
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Ansible | >= 2.7.0, < 2.7.15 |
| Redhat | Ansible Tower | 3.0 |
| Redhat | Ceph Storage | 3.0 |
| Redhat | Cloudforms Management Engine | 5.0 |
| Redhat | Enterprise Linux | 6.0 |
| Debian | Debian Linux | 10.0 |
| Opensuse | Backports Sle | 15.0 |
| Opensuse | Leap | 15.1 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.htmlMailing ListThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14864Issue TrackingPatchVendor Advisory
- https://github.com/ansible/ansible/issues/63522ExploitPatchThird Party Advisory
- https://github.com/ansible/ansible/pull/63527PatchVendor Advisory
- https://www.debian.org/security/2021/dsa-4950Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.htmlMailing ListThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14864Issue TrackingPatchVendor Advisory
- https://github.com/ansible/ansible/issues/63522ExploitPatchThird Party Advisory
- https://github.com/ansible/ansible/pull/63527PatchVendor Advisory
- https://www.debian.org/security/2021/dsa-4950Third Party Advisory
FAQ
What is CVE-2019-14864?
CVE-2019-14864 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used ...
How severe is CVE-2019-14864?
CVE-2019-14864 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-14864?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Ansible, Redhat Ansible Tower, Redhat Ceph Storage, Redhat Cloudforms Management Engine, Redhat Enterprise Linux.