Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14858

Опубликовано: 11 окт. 2019
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields will not be masked and will be displayed if Ansible is run with increased verbosity and present in the module invocation arguments for the task.

A flaw was found in ansible. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields will not be masked and will be displayed if Ansible is run with increased verbosity and present in the module invocation arguments for the task.

Отчет

Fixes for Red Hat OpenStack Platform (RHOSP) have been set to 'Moderate' because flaw exploitation requires running Ansible with increased verbosity which is not the RHOSP deployment default. Red Hat Gluster Storage no longer maintains its own version of Ansible. The fix will be provided from core Ansible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5ansibleNot affected
Red Hat Ansible Tower 3ansibleAffected
Red Hat Ceph Storage 2ansibleOut of support scope
Red Hat Ceph Storage 3ansibleAffected
Red Hat OpenStack Platform 10 (Newton)ansibleWill not fix
Red Hat OpenStack Platform 14 (Rocky)ansibleOut of support scope
Red Hat Satellite 6ansibleOut of support scope
Red Hat Storage 3ansibleWill not fix
Red Hat Ansible Engine 2.6 for RHEL 7ansibleFixedRHSA-2019:320124.10.2019
Red Hat Ansible Engine 2.7 for RHEL 7ansibleFixedRHSA-2019:320224.10.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-117->CWE-532
https://bugzilla.redhat.com/show_bug.cgi?id=1760593ansible: sub parameters marked as no_log are not masked in certain failure scenarios

EPSS

Процентиль: 18%
0.00059
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 6 лет назад

A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields will not be masked and will be displayed if Ansible is run with increased verbosity and present in the module invocation arguments for the task.

CVSS3: 5.5
nvd
больше 6 лет назад

A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields will not be masked and will be displayed if Ansible is run with increased verbosity and present in the module invocation arguments for the task.

CVSS3: 5.5
debian
больше 6 лет назад

A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible ...

CVSS3: 5.5
github
больше 3 лет назад

Ansible leaks sensitive information to logs when told not to

CVSS3: 7.3
fstec
больше 6 лет назад

Уязвимость системы управления конфигурациями Ansible, связанная с неправильной обработкой выходных данных для журналов регистрации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 18%
0.00059
Низкий

5 Medium

CVSS3