Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-14010

Опубликовано: 04 дек. 2025
Источник: debian
EPSS Низкий

Описание

A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ansiblefixed12.2.0+dfsg-1package
ansiblefixed12.0.0+dfsg-0+deb13u1trixiepackage
ansiblenot-affectedbookwormpackage
ansiblenot-affectedbullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2418774

  • https://github.com/ansible-community/ansible-build-data/blob/main/12/CHANGELOG-v12.md#security-fixes

  • https://github.com/ansible-collections/community.general/issues/11000

  • https://github.com/ansible-collections/community.general/pull/11005

EPSS

Процентиль: 2%
0.00013
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
2 месяца назад

A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.

CVSS3: 5.5
nvd
2 месяца назад

A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.

CVSS3: 5.5
github
2 месяца назад

Ansible Community General Collection is vulnerable to exposure of sensitive information

EPSS

Процентиль: 2%
0.00013
Низкий