ansible: secrets disclosed on logs when no_log enabled
Published Oct 8, 2019
8.5
HIGHCVSS 4.0
EPSS 0.51%
Description
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.
Affected products
-
- Version all ansible_engine-2.x and ansible_engine-3.x up to ansible_engine-3.5StatusaffectedConstraints-
- Version
Configuration 1
- < 2.6.20
- ≥ 2.7.0 · < 2.7.14
- ≥ 2.8.0 · < 2.8.6
Configuration 2
- 8.0
- 9.0
- 10.0
Configuration 3
- 15.0
- 15.1
Configuration 5
- 2.0
- 2.8.0
Running on/with
- 7.0
- 8.0
No data.
Red Hat Ansible Engine 2 for RHEL 7
ansible-0:2.8.6-1.el7ae
Fixed · RHSA-2019:3207
Red Hat Ansible Engine 2 for RHEL 8
ansible-0:2.8.6-1.el8ae
Fixed · RHSA-2019:3207
Red Hat Ansible Engine 2.6 for RHEL 7
ansible-0:2.6.20-1.el7ae
Fixed · RHSA-2019:3201
Red Hat Ansible Engine 2.7 for RHEL 7
ansible-0:2.7.14-1.el7ae
Fixed · RHSA-2019:3202
Red Hat Ansible Engine 2.8 for RHEL 7
ansible-0:2.8.6-1.el7ae
Fixed · RHSA-2019:3203
Red Hat Ansible Engine 2.8 for RHEL 8
ansible-0:2.8.6-1.el8ae
Fixed · RHSA-2019:3203
Red Hat OpenStack Platform 13.0 (Queens)
ansible-0:2.6.20-1.el7ae
Fixed · RHSA-2020:0756
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS
ansible-0:2.6.20-1.el7ae
Fixed · RHSA-2020:0756
CloudForms Management Engine 5
ansible
Not affected
Red Hat Ansible Tower 3
ansible
Affected
Red Hat Ceph Storage 2
ansible
Out of support scope
Red Hat Ceph Storage 3
ansible
Will not fix
Red Hat OpenStack Platform 10 (Newton)
ansible
Out of support scope
Red Hat OpenStack Platform 14 (Rocky)
ansible
Out of support scope
Red Hat Satellite 6
ansible
Not affected
Red Hat Storage 3
ansible
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Engine 2 for RHEL 7 | ansible-0:2.8.6-1.el7ae | Fixed | RHSA-2019:3207 |
| Red Hat Ansible Engine 2 for RHEL 8 | ansible-0:2.8.6-1.el8ae | Fixed | RHSA-2019:3207 |
| Red Hat Ansible Engine 2.6 for RHEL 7 | ansible-0:2.6.20-1.el7ae | Fixed | RHSA-2019:3201 |
| Red Hat Ansible Engine 2.7 for RHEL 7 | ansible-0:2.7.14-1.el7ae | Fixed | RHSA-2019:3202 |
| Red Hat Ansible Engine 2.8 for RHEL 7 | ansible-0:2.8.6-1.el7ae | Fixed | RHSA-2019:3203 |
| Red Hat Ansible Engine 2.8 for RHEL 8 | ansible-0:2.8.6-1.el8ae | Fixed | RHSA-2019:3203 |
| Red Hat OpenStack Platform 13.0 (Queens) | ansible-0:2.6.20-1.el7ae | Fixed | RHSA-2020:0756 |
| Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS | ansible-0:2.6.20-1.el7ae | Fixed | RHSA-2020:0756 |
| CloudForms Management Engine 5 | ansible | Not affected | n/a |
| Red Hat Ansible Tower 3 | ansible | Affected | n/a |
| Red Hat Ceph Storage 2 | ansible | Out of support scope | n/a |
| Red Hat Ceph Storage 3 | ansible | Will not fix | n/a |
| Red Hat OpenStack Platform 10 (Newton) | ansible | Out of support scope | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | ansible | Out of support scope | n/a |
| Red Hat Satellite 6 | ansible | Not affected | n/a |
| Red Hat Storage 3 | ansible | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Gluster Storage no more maintains its own version of Ansible, pre-requisite is to enable ansible repository. The fix will be consumed from core Ansible.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.51% (0.00513) | 41.61th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.51% (0.00509) | 39.14th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.13% (0.00127) | 29.54th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.07% (0.00074) | 34.11th | v3 (v2023.03.01) |
| Jun 10, 2024 | 0.04% (0.00045) | 14.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00045) | 12.06th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.28% (0.01282) | 68.34th | v2 (v2022.01.01) |
| Feb 22, 2023 | 1.28% (0.01282) | 68.05th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.28% (0.01282) | 65.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 5.62% (0.05620) | 76.71th | v2 (v2022.01.01) |
| Feb 3, 2022 | 10.99% (0.10990) | 88.00th | v1 |
| Jan 6, 2022 | 10.99% (0.10990) | 87.86th | v1 |
| Oct 11, 2021 | 2.68% (0.02678) | 79.59th | v1 |
| Sep 1, 2021 | 10.99% (0.10990) | 95.28th | v1 |
| Aug 8, 2021 | 10.99% (0.10990) | 0.00th | v1 |
| Apr 14, 2021 | 2.48% (0.02476) | 0.00th | v1 |
References (21)
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3201 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2019:3202 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2019:3203 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2019:3207 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2020:0756 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2019-14846 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1755373 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14846 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://github.com/advisories/GHSA-pm48-cvv2-29q5 Advisory
- https://github.com/ansible/ansible/commit/90e74dd2600e5cc42dd9b4f4656f3d651c4ce5c4
- https://github.com/ansible/ansible/commit/cb0f535a8b254a2daf69cd067e842fabb2993034
- https://github.com/ansible/ansible/commit/d961f676c01023a6a21503df16ba551a550e515b
- https://github.com/ansible/ansible/pull/63366 x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2019-4.yaml
- https://lists.debian.org/debian-lts-announce/2020/05/msg00005.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/01/msg00023.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-14846
- https://www.cve.org/CVERecord?id=CVE-2019-14846
- https://www.debian.org/security/2021/dsa-4950 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.