MEDIUM · 6.5

CVE-2019-14864

Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used ...

Vulnerability Description

Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
RedhatAnsible>= 2.7.0, < 2.7.15
RedhatAnsible Tower3.0
RedhatCeph Storage3.0
RedhatCloudforms Management Engine5.0
RedhatEnterprise Linux6.0
DebianDebian Linux10.0
OpensuseBackports Sle15.0
OpensuseLeap15.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-14864?

CVE-2019-14864 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used ...

How severe is CVE-2019-14864?

CVE-2019-14864 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-14864?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Ansible, Redhat Ansible Tower, Redhat Ceph Storage, Redhat Cloudforms Management Engine, Redhat Enterprise Linux.