CVE-2025-14010
This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes.
Does this matter?
Lower severity and a low EPSS score (0.14%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.14% probability · 3th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- redhat/community.general
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/CVE-2025-14010Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2418774Issue Tracking, Vendor Advisory
- https://github.com/ansible-collections/community.general/issues/11000
- https://github.com/ansible-collections/community.general/pull/11005
- https://github.com/ansible-community/ansible-build-data/blob/main/12/CHANGELOG-v12.md#security-fixes
- https://github.com/ansible-collections/community.general/issues/11000
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.