TROYANOSYVIRUS
Back to CVEs

CVE-2019-14864

MEDIUM
6.5

Description

Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.

CVE Details

CVSS v3.1 Score6.5
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published1/2/2020
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

debian:debian_linuxopensuse:backports_sleopensuse:leapredhat:ansibleredhat:ansible_towerredhat:ceph_storageredhat:cloudforms_management_engineredhat:enterprise_linux

Weaknesses (CWE)

CWE-117CWE-532CWE-532

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.