Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14858

Опубликовано: 11 окт. 2019
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields will not be masked and will be displayed if Ansible is run with increased verbosity and present in the module invocation arguments for the task.

A flaw was found in ansible. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields will not be masked and will be displayed if Ansible is run with increased verbosity and present in the module invocation arguments for the task.

Отчет

Fixes for Red Hat OpenStack Platform (RHOSP) have been set to 'Moderate' because flaw exploitation requires running Ansible with increased verbosity which is not the RHOSP deployment default. Red Hat Gluster Storage no longer maintains its own version of Ansible. The fix will be provided from core Ansible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5ansibleNot affected
Red Hat Ansible Tower 3ansibleAffected
Red Hat Ceph Storage 2ansibleOut of support scope
Red Hat Ceph Storage 3ansibleWill not fix
Red Hat OpenStack Platform 10 (Newton)ansibleWill not fix
Red Hat OpenStack Platform 14 (Rocky)ansibleOut of support scope
Red Hat Satellite 6ansibleOut of support scope
Red Hat Storage 3ansibleWill not fix
Red Hat Ansible Engine 2.6 for RHEL 7ansibleFixedRHSA-2019:320124.10.2019
Red Hat Ansible Engine 2.7 for RHEL 7ansibleFixedRHSA-2019:320224.10.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-215
https://bugzilla.redhat.com/show_bug.cgi?id=1760593ansible: sub parameters marked as no_log are not masked in certain failure scenarios

EPSS

Процентиль: 36%
0.00424
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 7 лет назад

A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields will not be masked and will be displayed if Ansible is run with increased verbosity and present in the module invocation arguments for the task.

CVSS3: 5.5
nvd
почти 7 лет назад

A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields will not be masked and will be displayed if Ansible is run with increased verbosity and present in the module invocation arguments for the task.

CVSS3: 5.5
debian
почти 7 лет назад

A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible ...

CVSS3: 5.5
github
около 4 лет назад

Ansible leaks sensitive information to logs when told not to

CVSS3: 7.3
fstec
почти 7 лет назад

Уязвимость системы управления конфигурациями Ansible, связанная с неправильной обработкой выходных данных для журналов регистрации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 36%
0.00424
Низкий

5 Medium

CVSS3