CVE-2019-14858
Ansible leaks sensitive information to logs when told not to
5.5
MEDIUM
CVSS 3.1
EPSS 0.43%
描述
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields will not be masked and will be displayed if Ansible is run with increased verbosity and present in the module invocation arguments for the task.
如何修補 CVE-2019-14858
要修補 CVE-2019-14858,請將受影響套件升級到下列已修補版本。
- —升級至 2.8.6-r0 或更新版本
- —升級至 2.8.6-r0 或更新版本
- —升級至 2.8.6+dfsg-1 或更新版本
- —升級至 2.9.0rc4 或更新版本
- —升級至 2.8.1 或更新版本
CVE-2019-14858 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(5)
- from 0, < 2.8.6-r0
- from 0, < 2.8.6-r0
- from 0, < 2.8.6+dfsg-1
- >= 2.9.0a1, < 2.9.0rc4
- >= 2.0, < 2.8.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | MEDIUM5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |