Sensitive information stored in logs In ansible
Description
Ansible Uses Plugins That Disclose Credentials Ansible, all ansible_engine-2.x versions and ansible_engine-3.x up to ansible_engine-3.5, was logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
pypi | 2.8.6 | ||
alpine v3.8 | 2.6.20-r0 | ||
debian 12 | 2.8.6+dfsg-1 | ||
debian 13 | 2.8.6+dfsg-1 | ||
alpine v3.10 | 2.8.6-r0 | ||
alpine v3.12 | 2.9.13-r0 | ||
alpine v3.9 | 2.7.14-r0 | ||
alpine v3.13 | 2.8.6-r0 | ||
alpine v3.14 | 2.8.6-r0 | ||
pypi | 2.6.20, 2.7.14, 2.8.6 |
1-10 of 12
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17.
References
1. 2. 3. 4. 5. 6. 7. 8. 9.