VDB
CVE-2019-14858
CVE-2019-14858
PUBLISHED
CVSS 7.300000190734863 HIGH
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields will not be masked and will be displayed if Ansible is run with increased verbosity and present in the module invocation arguments for the task.
EPSS 0.42% · 34.3th percentile
Risk Scores
CVSS 3.0
7.300000190734863
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.42%
34.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:18.04:LTS | ansible | 0, 2.3.1.0+dfsg-2, 2.5.1+dfsg-1 |
Timeline
- Oct 14, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 2, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 4, 2022 EPSS Score
- Jul 6, 2022 EPSS Score
- Sep 8, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-14858 third-party-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1760593 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-14858 third-party-advisory