CVE-2019-14846 PUBLISHED

In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.

EPSS 0.15% · 35.9th percentile

Risk Scores

EPSS Score
0.15%
35.9th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSansible0, 1.1+dfsg-1, 1.3.4+dfsg-1
Ubuntu:Pro:18.04:LTSansible2.5.1+dfsg-1ubuntu0.1+esm4, 0, 2.3.1.0+dfsg-2
Ubuntu:Pro:16.04:LTSansible2.0.0.2-2ubuntu1.3+esm2, 2.0.0.2-2ubuntu1.3+esm3, 2.0.0.2-2ubuntu1.3+esm4

Timeline

References

Open in Interactive Console →