CVE-2019-14864
Published: Jan 2, 2020
Modified: Aug 5, 2024
CVSS v3.0
5.7
Description
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
| Vendor | Product | Versions |
|---|---|---|
Red Hat | Ansible | affected Ansible versions 2.9.x before 2.9.1affected Ansible versions 2.8.x before 2.8.7affected Ansible versions 2.7.x before 2.7.15 |
CVSS v3.0 Details
CVSS v3.0 Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now