Information disclosure in Ansible - CVE-2019-14864
Published: November 20, 2019
Vulnerability identifier: #VU22872
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14864
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to the Splunk and Sumologic callback plugins write sensitive information into log files. A local user with ability to read log files can gain access to sensitive information.
Affected software
Ansible
ansible (Debian package)
ansible (Alpine package)
SUSE Linux
Opensuse
ansible (Debian package)
ansible (Alpine package)
SUSE Linux
Opensuse
How to mitigate CVE-2019-14864
Install updates from vendor's website.
Ansible - addressed in versions 2.7.15, 2.8.7, 2.9.1
ansible (Debian package) - update to 2.7.7+dfsg-1+deb10u1
ansible (Alpine package) - addressed in versions 2.7.16-r0, 2.8.8-r0
ansible (Debian package) - update to 2.7.7+dfsg-1+deb10u1
ansible (Alpine package) - addressed in versions 2.7.16-r0, 2.8.8-r0
External References
- https://access.redhat.com/errata/RHSA-2019:3925
- https://github.com/ansible/ansible/blob/v2.7.15/changelogs/CHANGELOG-v2.7.rst
- https://bugzilla.redhat.com/show_bug.cgi?id=1764148
- https://access.redhat.com/errata/RHSA-2019:3926
- https://access.redhat.com/errata/RHSA-2019:3927
- https://access.redhat.com/errata/RHSA-2019:3928