First published: Wed Sep 25 2019(Updated: )
Ansible, all ansible_engine-2.x versions and ansible_engine-3.x up to ansible_engine-3.5, was logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Ansible Engine | <2.6.20 | |
Redhat Ansible Engine | >=2.7.0<2.7.14 | |
Redhat Ansible Engine | >=2.8.0<2.8.6 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
openSUSE Backports SLE | =15.0-sp1 | |
openSUSE Leap | =15.1 | |
Redhat Openstack | =13 | |
Redhat Ansible Engine | =2.0 | |
Redhat Ansible Engine | =2.8.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Server | =8.0 | |
debian/ansible | 2.7.7+dfsg-1+deb10u1 2.7.7+dfsg-1+deb10u2 2.10.7+merged+base+2.10.8+dfsg-1 7.3.0+dfsg-1 7.7.0+dfsg-3 | |
redhat/ansible-engine | <2.8.6 | 2.8.6 |
redhat/ansible-engine | <2.7.14 | 2.7.14 |
redhat/ansible-engine | <2.6.20 | 2.6.20 |
pip/ansible | >=2.8.0a1<2.8.6 | 2.8.6 |
pip/ansible | >=2.7.0a1<2.7.14 | 2.7.14 |
pip/ansible | >=0<2.6.20 | 2.6.20 |
All of | ||
Any of | ||
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Server | =8.0 | |
Any of | ||
Redhat Ansible Engine | =2.0 | |
Redhat Ansible Engine | =2.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Ansible vulnerability is CVE-2019-14846.
The severity of CVE-2019-14846 is high.
All Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19 are affected by CVE-2019-14846.
To fix CVE-2019-14846, update to ansible-engine 2.8.6 for ansible-engine 2.8.x, ansible-engine 2.7.14 for ansible-engine 2.7.x, ansible-engine 2.6.20 for ansible-engine 2.6.x. For ansible-core, update to ansible-core 2.8.6. Check the provided references for more information.
No, Ansible modules are not affected by CVE-2019-14846.