Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-14846

Опубликовано: 08 окт. 2019
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 2.1
CVSS3: 7.8

Описание

In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

2.8.6+dfsg-1
disco

ignored

end of life
eoan

ignored

end of life
esm-apps/bionic

released

2.5.1+dfsg-1ubuntu0.1+esm5
esm-apps/focal

not-affected

2.8.6+dfsg-1
esm-apps/jammy

not-affected

2.8.6+dfsg-1
esm-apps/noble

not-affected

2.8.6+dfsg-1
esm-apps/xenial

released

2.0.0.2-2ubuntu1.3+esm5
esm-infra-legacy/trusty

released

1.5.4+dfsg-1ubuntu0.1~esm3

Показывать по

EPSS

Процентиль: 36%
0.00153
Низкий

2.1 Low

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
redhat
больше 6 лет назад

In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.

CVSS3: 7.8
nvd
больше 6 лет назад

In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.

CVSS3: 7.8
debian
больше 6 лет назад

In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, an ...

CVSS3: 7.8
github
больше 3 лет назад

Ansible Uses Plugins That Disclose Credentials

CVSS3: 5.5
fstec
больше 6 лет назад

Уязвимость системы управления конфигурациями Ansible, связана с раскрытием информации через регистрационные файлы, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 36%
0.00153
Низкий

2.1 Low

CVSS2

7.8 High

CVSS3