CVE-2019-14864
MEDIUMRedhat Ansible < 2.7.15 - Log Information Exposure
Title source: ruleDescription
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
References (6)
Scores
CVSS v3
6.5
EPSS
0.0089
EPSS Percentile
75.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-532
CWE-117
Status
published
Products (11)
debian/debian_linux
10.0
opensuse/backports_sle
15.0 sp1
opensuse/leap
15.1
pypi/ansible
2.7.0a1 - 2.7.15PyPI
redhat/ansible
2.7.0 - 2.7.15
redhat/ansible_tower
3.0
redhat/ceph_storage
3.0
redhat/cloudforms_management_engine
5.0
redhat/enterprise_linux
6.0
redhat/enterprise_linux
7.0
... and 1 more
Published
Jan 02, 2020
Tracked Since
Feb 18, 2026