Insertion of Sensitive Information into Log File and Improper Output Neutralization for Logs in ansible
Moderate severity
GitHub Reviewed
Published
Feb 9, 2022
to the GitHub Advisory Database
•
Updated Sep 5, 2024
Package
Affected versions
< 2.8.14
>= 2.9.0a1, < 2.9.12
>= 2.10.0a1, < 2.10.1rc2
Patched versions
2.8.14
2.9.12
2.10.1rc2
Description
Published by the National Vulnerability Database
Sep 11, 2020
Reviewed
Apr 2, 2021
Published to the GitHub Advisory Database
Feb 9, 2022
Last updated
Sep 5, 2024
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.
References