Ansible: Splunk and Sumologic callback plugins leak sensitive data in logs
Published Jan 2, 2020
6.5
MEDIUMCVSS 3.1
EPSS 1.87%
Description
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
Affected products
-
- Version Ansible versions 2.7.x before 2.7.15StatusaffectedConstraints-
- Version Ansible versions 2.8.x before 2.8.7StatusaffectedConstraints-
- Version Ansible versions 2.9.x before 2.9.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Configuration 1
- ≥ 2.7.0 · < 2.7.15
- ≥ 2.8.0 · < 2.8.7
- ≥ 2.9.0 · < 2.9.1
- 3.0
- 3.0
- 5.0
Configuration 2
- 6.0
- 7.0
- 8.0
Configuration 3
- 10.0
Configuration 4
- 15.0
- 15.1
No data.
Red Hat Ansible Engine 2 for RHEL 7
ansible-0:2.9.1-1.el7
Fixed · RHSA-2019:3928
Red Hat Ansible Engine 2 for RHEL 8
ansible-0:2.9.1-1.el8
Fixed · RHSA-2019:3928
Red Hat Ansible Engine 2.7 for RHEL 7
ansible-0:2.7.15-1.el7ae
Fixed · RHSA-2019:3925
Red Hat Ansible Engine 2.8 for RHEL 7
ansible-0:2.8.7-1.el7ae
Fixed · RHSA-2019:3926
Red Hat Ansible Engine 2.8 for RHEL 8
ansible-0:2.8.7-1.el8ae
Fixed · RHSA-2019:3926
Red Hat Ansible Engine 2.9 for RHEL 7
ansible-0:2.9.1-1.el7
Fixed · RHSA-2019:3927
Red Hat Ansible Engine 2.9 for RHEL 8
ansible-0:2.9.1-1.el8
Fixed · RHSA-2019:3927
CloudForms Management Engine 5
ansible
Not affected
Red Hat Ansible Tower 3
ansible
Not affected
Red Hat Ceph Storage 2
ansible
Out of support scope
Red Hat Ceph Storage 3
ansible
Will not fix
Red Hat OpenStack Platform 10 (Newton)
ansible
Will not fix
Red Hat OpenStack Platform 13 (Queens)
ansible
Will not fix
Red Hat OpenStack Platform 14 (Rocky)
ansible
Will not fix
Red Hat Satellite 6
ansible
Out of support scope
Red Hat Storage 3
ansible
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Engine 2 for RHEL 7 | ansible-0:2.9.1-1.el7 | Fixed | RHSA-2019:3928 |
| Red Hat Ansible Engine 2 for RHEL 8 | ansible-0:2.9.1-1.el8 | Fixed | RHSA-2019:3928 |
| Red Hat Ansible Engine 2.7 for RHEL 7 | ansible-0:2.7.15-1.el7ae | Fixed | RHSA-2019:3925 |
| Red Hat Ansible Engine 2.8 for RHEL 7 | ansible-0:2.8.7-1.el7ae | Fixed | RHSA-2019:3926 |
| Red Hat Ansible Engine 2.8 for RHEL 8 | ansible-0:2.8.7-1.el8ae | Fixed | RHSA-2019:3926 |
| Red Hat Ansible Engine 2.9 for RHEL 7 | ansible-0:2.9.1-1.el7 | Fixed | RHSA-2019:3927 |
| Red Hat Ansible Engine 2.9 for RHEL 8 | ansible-0:2.9.1-1.el8 | Fixed | RHSA-2019:3927 |
| CloudForms Management Engine 5 | ansible | Not affected | n/a |
| Red Hat Ansible Tower 3 | ansible | Not affected | n/a |
| Red Hat Ceph Storage 2 | ansible | Out of support scope | n/a |
| Red Hat Ceph Storage 3 | ansible | Will not fix | n/a |
| Red Hat OpenStack Platform 10 (Newton) | ansible | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | ansible | Will not fix | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | ansible | Will not fix | n/a |
| Red Hat Satellite 6 | ansible | Out of support scope | n/a |
| Red Hat Storage 3 | ansible | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
* The exploitation of this flaw depends on the use of either Sumo Logic or Splunk callback plugins. However, because Red Hat OpenStack Platform (RHOSP) does not use Sumo Logic or Splunk, Red Hat will not be providing a fix for RHOSP Ansible at this time. * Red Hat Gluster Storage no more maintains its own version of Ansible, pre-requisite is to enable ansible repository. The fix will be consumed from core Ansible. * Ansible Tower’s Splunk logging integration uses the Splunk HTTP Collector and Ansible Engine. * The exploitation of this flaw depends on the use of either Sumo Logic or Splunk callback plugins. However, because Red Hat Satellite 6.4 and 6.5 do not use Sumo Logic or Splunk, Red Hat will not be providing a fix for Satellite 6.4 and 6.5 and Ansible at this time. Users may upgrade to Satellite 6.6 or later which includes the resolution to this bug if desired.
References (19)
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-14864 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1764148 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14864 x_refsource_CONFIRMIssue TrackingPatchVendor Advisory
- https://github.com/advisories/GHSA-3m93-m4q6-mc6v Advisory
- https://github.com/ansible/ansible/commit/050f92f96054bf59e283fdec9972323c2ed00348
- https://github.com/ansible/ansible/commit/75288a89d0053d6df35c90863fb6c9542d89850e
- https://github.com/ansible/ansible/commit/a0ec2976b2716cdecdd7a8f416d96406acd79b7c
- https://github.com/ansible/ansible/commit/c76e074e4c71c7621a1ca8159261c1959b5287af
- https://github.com/ansible/ansible/issues/63522 x_refsource_MISCExploitPatchThird Party Advisory
- https://github.com/ansible/ansible/pull/63527 x_refsource_MISCPatchVendor Advisory
- https://github.com/ansible/ansible/pull/64273
- https://github.com/ansible/ansible/pull/64274
- https://github.com/ansible/ansible/pull/64748
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2020-160.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2019-14864
- https://www.cve.org/CVERecord?id=CVE-2019-14864
- https://www.debian.org/security/2021/dsa-4950 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.