CVE-2019-14864
MEDIUMRedhat Ansible < 2.7.15 - Log Information Exposure
Title source: ruleDescription
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
References (6)
Scores
CVSS v3
6.5
EPSS
0.0101
EPSS Percentile
76.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-532
CWE-117
Status
published
Affected Products (11)
redhat/ansible
< 2.7.15
redhat/ansible_tower
redhat/ceph_storage
redhat/cloudforms_management_engine
redhat/enterprise_linux
redhat/enterprise_linux
redhat/enterprise_linux
debian/debian_linux
opensuse/backports_sle
opensuse/leap
pypi/ansible
< 2.7.15PyPI
Timeline
Published
Jan 02, 2020
Tracked Since
Feb 18, 2026