Information Exposure Through Log Files Affecting ansible package, versions <2.8.6-r0
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-ALPINE312-ANSIBLE-589785
- published 14 Oct 2019
- disclosed 14 Oct 2019
How to fix?
Upgrade Alpine:3.12 ansible to version 2.8.6-r0 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream ansible package and not the ansible package as distributed by Alpine.
See How to fix? for Alpine:3.12 relevant fixed versions and status.
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields will not be masked and will be displayed if Ansible is run with increased verbosity and present in the module invocation arguments for the task.
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14858
- https://security-tracker.debian.org/tracker/CVE-2019-14858
- https://access.redhat.com/errata/RHSA-2020:0756
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14858
- https://access.redhat.com/errata/RHSA-2019:3201
- https://access.redhat.com/errata/RHSA-2019:3202
- https://access.redhat.com/errata/RHSA-2019:3203
- https://access.redhat.com/errata/RHSA-2019:3207
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.html
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.html