Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14864 | patch vendor advisory issue tracking |
https://github.com/ansible/ansible/issues/63522 | patch third party advisory exploit |
https://github.com/ansible/ansible/pull/63527 | patch vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.html | vendor advisory mailing list third party advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.html | vendor advisory mailing list third party advisory |
https://www.debian.org/security/2021/dsa-4950 | third party advisory vendor advisory |