First published: Thu Jan 02 2020(Updated: )
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/ansible | 2.7.7+dfsg-1+deb10u1 2.7.7+dfsg-1+deb10u2 2.10.7+merged+base+2.10.8+dfsg-1 7.3.0+dfsg-1 7.7.0+dfsg-3 | |
Redhat Ansible | >=2.7.0<2.7.15 | |
Redhat Ansible | >=2.8.0<2.8.7 | |
Redhat Ansible | >=2.9.0<2.9.1 | |
Redhat Ansible Tower | =3.0 | |
Redhat Ceph Storage | =3.0 | |
Redhat Cloudforms Management Engine | =5.0 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =8.0 | |
Debian Debian Linux | =10.0 | |
openSUSE Backports SLE | =15.0-sp1 | |
openSUSE Leap | =15.1 | |
pip/ansible | >=2.9.0a1<2.9.1 | 2.9.1 |
pip/ansible | >=2.8.0a1<2.8.7 | 2.8.7 |
pip/ansible | >=2.7.0a1<2.7.15 | 2.7.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14864 is a vulnerability in Ansible versions 2.9.x before 2.9.1, 2.8.x before 2.8.7, and 2.7.x before 2.7.15.
CVE-2019-14864 has a severity rating of 6.5 (medium).
CVE-2019-14864 affects Ansible by not respecting the flag no_log when Sumologic and Splunk callback plugins are used, potentially exposing and collecting sensitive data.
CVE-2019-14864 affects Ansible versions 2.7.x, 2.8.x, and 2.9.x.
To fix CVE-2019-14864, upgrade to Ansible versions 2.9.1, 2.8.7, or 2.7.15.