Back

HIGH

Ansible: gcp modules do not flag sensitive data fields properly

Published Nov 25, 2019

Description

A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for all gcp modules is not setting no_log to True. Any sensitive data managed by that function would be leak as an output when running ansible playbooks.

Affected products

Remediation

Red Hat statement

Ansible shipped with Red Hat Ceph Storage 3; Red Hat OpenStack 10, 13, and 14; and Ansible Engine 2.6 and 2.7 are not vulnerable as they do not include the cred_type implementation (service_account_contents).

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 25, 2019
Updated Aug 4, 2024
Reserved Mar 27, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 26, 2019
ENISA EUVD
Assigner redhat
Published Nov 25, 2019
Updated Aug 4, 2024
Exploited since n/a
EUVD-2019-0007 GHSA-P75J-WC34-527C