CVE-2018-10855
When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.
Does this matter?
Lower severity and a low EPSS score (3.11%). Track it; it rarely justifies an emergency change on its own.
Description
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 3.11% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- redhat/ansible engine · redhat/cloudforms · redhat/openstack · redhat/virtualization · debian/debian linux · canonical/ubuntu linux
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHBA-2018:3788Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1948Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1949Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2022Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2079Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2184Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2585Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0054Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10855Issue Tracking, Vendor Advisory
- https://usn.ubuntu.com/4072-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4396Third Party Advisory
- https://access.redhat.com/errata/RHBA-2018:3788Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1948Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1949Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2022Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2079Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2184Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2585Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0054Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10855Issue Tracking, Vendor Advisory
- https://usn.ubuntu.com/4072-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4396Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.