Inclusion of Sensitive Information in Log Files and Improper Output Neutralization for Logs in Ansible
Moderate severity
GitHub Reviewed
Published
Feb 26, 2020
to the GitHub Advisory Database
•
Updated Sep 4, 2024
Package
Affected versions
>= 2.7.0a1, < 2.7.15
>= 2.8.0a1, < 2.8.7
>= 2.9.0a1, < 2.9.1
Patched versions
2.7.15
2.8.7
2.9.1
Description
Published by the National Vulnerability Database
Jan 2, 2020
Reviewed
Feb 25, 2020
Published to the GitHub Advisory Database
Feb 26, 2020
Last updated
Sep 4, 2024
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
References