ansible: Failed tasks do not honour no_log option allowing for secrets to be disclosed in logs
Published Jul 2, 2018
8.2
HIGHCVSS 4.0
EPSS 3.11%
Description
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.
Affected products
- Vendor n/a Product Ansible Defaultn/a
- Version Ansible 2.4.5StatusaffectedConstraints-
- Version Ansible 2.5.5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | Ansible | n/a |
|
Configuration 1
- ≥ 2.4 · < 2.4.5
- > 2.5 · ≤ 2.5.5
- 2.0
- 4.6
- 13
- 4.0
Configuration 2
- 9.0
Configuration 4
- 16.04
- 18.04
- 19.04
No data.
CloudForms Management Engine 5.9
ansible-0:2.4.5.0-1.el7ae
Fixed · RHSA-2018:2184
CloudForms Management Engine 5.9
ansible-tower-0:3.2.5-1.el7at
Fixed · RHSA-2018:2184
CloudForms Management Engine 5.9
cfme-0:5.9.3.4-1.el7cf
Fixed · RHSA-2018:2184
CloudForms Management Engine 5.9
cfme-amazon-smartstate-0:5.9.3.4-1.el7cf
Fixed · RHSA-2018:2184
CloudForms Management Engine 5.9
cfme-appliance-0:5.9.3.4-1.el7cf
Fixed · RHSA-2018:2184
CloudForms Management Engine 5.9
cfme-gemset-0:5.9.3.4-1.el7cf
Fixed · RHSA-2018:2184
CloudForms Management Engine 5.9
httpd-configmap-generator-0:0.2.2-1.1.el7cf
Fixed · RHSA-2018:2184
Red Hat Ansible Engine 2 for RHEL 7
ansible-0:2.5.5-1.el7ae
Fixed · RHSA-2018:1948
Red Hat Ansible Engine 2.4 for RHEL 7
ansible-0:2.4.5.0-1.el7ae
Fixed · RHSA-2018:2022
Red Hat Ansible Engine 2.5 for RHEL 7
ansible-0:2.5.5-1.el7ae
Fixed · RHSA-2018:1949
Red Hat OpenStack Platform 10.0 (Newton)
ansible-0:2.4.6.0-1.el7ae
Fixed · RHSA-2019:0054
Red Hat OpenStack Platform 12.0 (Pike)
ansible-0:2.4.6.0-1.el7ae
Fixed · RHBA-2018:3788
Red Hat OpenStack Platform 12.0 (Pike)
ansible-role-redhat-subscription-0:1.0.1-4.el7ost
Fixed · RHBA-2018:3788
Red Hat OpenStack Platform 13.0 (Queens)
ansible-0:2.4.6.0-1.el7ae
Fixed · RHSA-2018:2585
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
imgbased-0:1.0.20-0.1.el7ev
Fixed · RHSA-2018:2079
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-release-virtualization-host-0:4.2-4.3.el7
Fixed · RHSA-2018:2079
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-virtualization-host-0:4.2-20180622.0
Fixed · RHSA-2018:2079
Red Hat Ceph Storage 2
ansible
Will not fix
Red Hat Ceph Storage 3
ansible
Will not fix
Red Hat OpenShift Enterprise 3
ansible
Not affected
Red Hat Quickstart Cloud Installer 1
ansible
Will not fix
Red Hat Satellite 6
ansible
Will not fix
Red Hat Storage 3
ansible
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5.9 | ansible-0:2.4.5.0-1.el7ae | Fixed | RHSA-2018:2184 |
| CloudForms Management Engine 5.9 | ansible-tower-0:3.2.5-1.el7at | Fixed | RHSA-2018:2184 |
| CloudForms Management Engine 5.9 | cfme-0:5.9.3.4-1.el7cf | Fixed | RHSA-2018:2184 |
| CloudForms Management Engine 5.9 | cfme-amazon-smartstate-0:5.9.3.4-1.el7cf | Fixed | RHSA-2018:2184 |
| CloudForms Management Engine 5.9 | cfme-appliance-0:5.9.3.4-1.el7cf | Fixed | RHSA-2018:2184 |
| CloudForms Management Engine 5.9 | cfme-gemset-0:5.9.3.4-1.el7cf | Fixed | RHSA-2018:2184 |
| CloudForms Management Engine 5.9 | httpd-configmap-generator-0:0.2.2-1.1.el7cf | Fixed | RHSA-2018:2184 |
| Red Hat Ansible Engine 2 for RHEL 7 | ansible-0:2.5.5-1.el7ae | Fixed | RHSA-2018:1948 |
| Red Hat Ansible Engine 2.4 for RHEL 7 | ansible-0:2.4.5.0-1.el7ae | Fixed | RHSA-2018:2022 |
| Red Hat Ansible Engine 2.5 for RHEL 7 | ansible-0:2.5.5-1.el7ae | Fixed | RHSA-2018:1949 |
| Red Hat OpenStack Platform 10.0 (Newton) | ansible-0:2.4.6.0-1.el7ae | Fixed | RHSA-2019:0054 |
| Red Hat OpenStack Platform 12.0 (Pike) | ansible-0:2.4.6.0-1.el7ae | Fixed | RHBA-2018:3788 |
| Red Hat OpenStack Platform 12.0 (Pike) | ansible-role-redhat-subscription-0:1.0.1-4.el7ost | Fixed | RHBA-2018:3788 |
| Red Hat OpenStack Platform 13.0 (Queens) | ansible-0:2.4.6.0-1.el7ae | Fixed | RHSA-2018:2585 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | imgbased-0:1.0.20-0.1.el7ev | Fixed | RHSA-2018:2079 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-release-virtualization-host-0:4.2-4.3.el7 | Fixed | RHSA-2018:2079 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-virtualization-host-0:4.2-20180622.0 | Fixed | RHSA-2018:2079 |
| Red Hat Ceph Storage 2 | ansible | Will not fix | n/a |
| Red Hat Ceph Storage 3 | ansible | Will not fix | n/a |
| Red Hat OpenShift Enterprise 3 | ansible | Not affected | n/a |
| Red Hat Quickstart Cloud Installer 1 | ansible | Will not fix | n/a |
| Red Hat Satellite 6 | ansible | Will not fix | n/a |
| Red Hat Storage 3 | ansible | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Gluster Storage 3 and Red Hat Ceph Storage 3 ships the affected version of ansible, but they no longer maintain their own version of ansible. Both the products will consume fixes directly from ansible repository.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
AV:N/AC:M/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 3.11% (0.03113) | 87.36th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.09% (0.03088) | 85.96th | v5 (v2026.06.15) |
| May 31, 2025 | 3.18% (0.03179) | 86.34th | v4 (v2025.03.14) |
| Mar 30, 2025 | 2.02% (0.02015) | 82.13th | v4 (v2025.03.14) |
| Mar 29, 2025 | 3.86% (0.03857) | 80.06th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.02% (0.02015) | 82.54th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.35% (0.00349) | 72.63th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.35% (0.00349) | 70.99th | v3 (v2023.03.01) |
| Jan 2, 2024 | 0.35% (0.00349) | 68.81th | v3 (v2023.03.01) |
| Nov 23, 2023 | 0.36% (0.00357) | 69.04th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.37% (0.00373) | 69.24th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.44% (0.00440) | 70.82th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.54% (0.01537) | 74.52th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.54% (0.01537) | 51.33th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.48% (0.02476) | 54.92th | v5 (v2026.06.15) |
| Apr 14, 2021 | 2.48% (0.02476) | 0.00th | v1 |
References (18)
- https://access.redhat.com/errata/RHBA-2018:3788 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1948 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1949 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2022 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2079 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2184 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2585 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0054 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2018-10855 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1588855 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10855 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://github.com/advisories/GHSA-jwcc-j78w-j73w Advisory
- https://github.com/ansible/ansible/pull/41414
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2018-42.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2018-10855
- https://usn.ubuntu.com/4072-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-10855
- https://www.debian.org/security/2019/dsa-4396 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.