SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-14864

This would discloses and collects any sensitive data.

MEDIUM 6.5EPSS 1.87%

Does this matter?

Lower severity and a low EPSS score (1.87%). Track it; it rarely justifies an emergency change on its own.

Description

Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.87% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-117, CWE-532
Affected
redhat/ansible · redhat/ansible tower · redhat/ceph storage · redhat/cloudforms management engine · redhat/enterprise linux · debian/debian linux · opensuse/backports sle · opensuse/leap
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.