CVE-2019-14864: Medium severity red hat ansible vulnerability
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag nolog set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-14864?
CVE-2019-14864 is a vulnerability in Ansible versions 2.9.x before 2.9.1, 2.8.x before 2.8.7, and 2.7.x before 2.7.15.
What is the severity of CVE-2019-14864?
CVE-2019-14864 has a severity rating of 6.5 (medium).
How does CVE-2019-14864 affect Ansible?
CVE-2019-14864 affects Ansible by not respecting the flag no_log when Sumologic and Splunk callback plugins are used, potentially exposing and collecting sensitive data.
What software versions are affected by CVE-2019-14864?
CVE-2019-14864 affects Ansible versions 2.7.x, 2.8.x, and 2.9.x.
How can CVE-2019-14864 be fixed?
To fix CVE-2019-14864, upgrade to Ansible versions 2.9.1, 2.8.7, or 2.7.15.