Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14846

Опубликовано: 08 окт. 2019
Источник: redhat
CVSS3: 7.3

Описание

In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.

Ansible was logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.

Отчет

Red Hat Gluster Storage no more maintains its own version of Ansible, pre-requisite is to enable ansible repository. The fix will be consumed from core Ansible.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5ansibleNot affected
Red Hat Ansible Tower 3ansibleAffected
Red Hat Ceph Storage 2ansibleOut of support scope
Red Hat Ceph Storage 3ansibleAffected
Red Hat OpenStack Platform 10 (Newton)ansibleOut of support scope
Red Hat OpenStack Platform 14 (Rocky)ansibleOut of support scope
Red Hat Satellite 6ansibleNot affected
Red Hat Storage 3ansibleWill not fix
Red Hat Ansible Engine 2.6 for RHEL 7ansibleFixedRHSA-2019:320124.10.2019
Red Hat Ansible Engine 2.7 for RHEL 7ansibleFixedRHSA-2019:320224.10.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-117->CWE-532
https://bugzilla.redhat.com/show_bug.cgi?id=1755373ansible: secrets disclosed on logs when no_log enabled

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 6 лет назад

In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.

CVSS3: 7.8
nvd
больше 6 лет назад

In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.

CVSS3: 7.8
debian
больше 6 лет назад

In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, an ...

CVSS3: 7.8
github
больше 3 лет назад

Ansible Uses Plugins That Disclose Credentials

CVSS3: 5.5
fstec
больше 6 лет назад

Уязвимость системы управления конфигурациями Ansible, связана с раскрытием информации через регистрационные файлы, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

7.3 High

CVSS3