CVE-2019-14864

MEDIUM

Redhat Ansible < 2.7.15 - Log Information Exposure

Title source: rule

Description

Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.

Scores

CVSS v3 6.5
EPSS 0.0101
EPSS Percentile 76.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-532 CWE-117
Status published

Affected Products (11)

redhat/ansible < 2.7.15
redhat/ansible_tower
redhat/ceph_storage
redhat/cloudforms_management_engine
redhat/enterprise_linux
redhat/enterprise_linux
redhat/enterprise_linux
debian/debian_linux
opensuse/backports_sle
opensuse/leap
pypi/ansible < 2.7.15PyPI

Timeline

Published Jan 02, 2020
Tracked Since Feb 18, 2026