ZeroHour

CVE-2019-14864

PoC
CVSS 3.1
6.5 medium
EPSS
2%p78
Published
()
Modified
Description

Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.

Vendors
redhatdebianopensuse
Products
ansible, ansible tower, ceph storage, cloudforms management engine, enterprise linux, debian linux, backports sle, leap
Weakness
CWE-117, CWE-532
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.