ansible: sub parameters marked as no_log are not masked in certain failure scenarios
Published Oct 14, 2019
6.8
MEDIUMCVSS 4.0
EPSS 0.42%
Description
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields will not be masked and will be displayed if Ansible is run with increased verbosity and present in the module invocation arguments for the task.
Affected products
-
- Version ansible_engine-2.x up to 2.8StatusaffectedConstraints-
- Version ansible_tower-3.x up to 3.5StatusaffectedConstraints-
- Version
- ≥ 2.0 · ≤ 2.8.0
- ≥ 3.0 · ≤ 3.5.0
No data.
Red Hat Ansible Engine 2 for RHEL 7
ansible-0:2.8.6-1.el7ae
Fixed · RHSA-2019:3207
Red Hat Ansible Engine 2 for RHEL 8
ansible-0:2.8.6-1.el8ae
Fixed · RHSA-2019:3207
Red Hat Ansible Engine 2.6 for RHEL 7
ansible-0:2.6.20-1.el7ae
Fixed · RHSA-2019:3201
Red Hat Ansible Engine 2.7 for RHEL 7
ansible-0:2.7.14-1.el7ae
Fixed · RHSA-2019:3202
Red Hat Ansible Engine 2.8 for RHEL 7
ansible-0:2.8.6-1.el7ae
Fixed · RHSA-2019:3203
Red Hat Ansible Engine 2.8 for RHEL 8
ansible-0:2.8.6-1.el8ae
Fixed · RHSA-2019:3203
Red Hat OpenStack Platform 13.0 (Queens)
ansible-0:2.6.20-1.el7ae
Fixed · RHSA-2020:0756
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS
ansible-0:2.6.20-1.el7ae
Fixed · RHSA-2020:0756
CloudForms Management Engine 5
ansible
Not affected
Red Hat Ansible Tower 3
ansible
Affected
Red Hat Ceph Storage 2
ansible
Out of support scope
Red Hat Ceph Storage 3
ansible
Will not fix
Red Hat OpenStack Platform 10 (Newton)
ansible
Will not fix
Red Hat OpenStack Platform 14 (Rocky)
ansible
Out of support scope
Red Hat Satellite 6
ansible
Out of support scope
Red Hat Storage 3
ansible
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Engine 2 for RHEL 7 | ansible-0:2.8.6-1.el7ae | Fixed | RHSA-2019:3207 |
| Red Hat Ansible Engine 2 for RHEL 8 | ansible-0:2.8.6-1.el8ae | Fixed | RHSA-2019:3207 |
| Red Hat Ansible Engine 2.6 for RHEL 7 | ansible-0:2.6.20-1.el7ae | Fixed | RHSA-2019:3201 |
| Red Hat Ansible Engine 2.7 for RHEL 7 | ansible-0:2.7.14-1.el7ae | Fixed | RHSA-2019:3202 |
| Red Hat Ansible Engine 2.8 for RHEL 7 | ansible-0:2.8.6-1.el7ae | Fixed | RHSA-2019:3203 |
| Red Hat Ansible Engine 2.8 for RHEL 8 | ansible-0:2.8.6-1.el8ae | Fixed | RHSA-2019:3203 |
| Red Hat OpenStack Platform 13.0 (Queens) | ansible-0:2.6.20-1.el7ae | Fixed | RHSA-2020:0756 |
| Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS | ansible-0:2.6.20-1.el7ae | Fixed | RHSA-2020:0756 |
| CloudForms Management Engine 5 | ansible | Not affected | n/a |
| Red Hat Ansible Tower 3 | ansible | Affected | n/a |
| Red Hat Ceph Storage 2 | ansible | Out of support scope | n/a |
| Red Hat Ceph Storage 3 | ansible | Will not fix | n/a |
| Red Hat OpenStack Platform 10 (Newton) | ansible | Will not fix | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | ansible | Out of support scope | n/a |
| Red Hat Satellite 6 | ansible | Out of support scope | n/a |
| Red Hat Storage 3 | ansible | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Fixes for Red Hat OpenStack Platform (RHOSP) have been set to 'Moderate' because flaw exploitation requires running Ansible with increased verbosity which is not the RHOSP deployment default. Red Hat Gluster Storage no longer maintains its own version of Ansible. The fix will be provided from core Ansible.
References (19)
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.html vendor-advisoryx_refsource_SUSE
- https://access.redhat.com/errata/RHSA-2019:3201 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:3202 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:3203 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:3207 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2020:0756 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-14858 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1760593 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14858 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://github.com/advisories/GHSA-h653-95qw-h2mp Advisory
- https://github.com/ansible/ansible/commit/0fd656e9964a91f2e8b1e9bbf78c74661ab9d37b
- https://github.com/ansible/ansible/commit/3dfb8e81bb5f776a6b00c7a90dd087e85b71f8bb
- https://github.com/ansible/ansible/commit/87f8d77d70476454f7fe2381bd363a329ce4266c
- https://github.com/ansible/ansible/commit/f610ed3a4eb87eb557200606279796921fa9b722
- https://github.com/ansible/ansible/pull/63405
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2019-171.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2019-14858
- https://www.cve.org/CVERecord?id=CVE-2019-14858
Change history (0)
No recorded changes yet.