SB2019102430 - Inclusion of Sensitive Information in Log Files in ansible (Alpine package)
Published: October 24, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2019-14846)
The vulnerability allows a local authenticated user to execute arbitrary code.
Ansible, all ansible_engine-2.x versions and ansible_engine-3.x up to ansible_engine-3.5, was logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=1243e4504e5eab5e6253188c8d16667508820289
- https://git.alpinelinux.org/aports/commit/?id=b67a373492fd24911338d12cb9c2ede52b65ccf9
- https://git.alpinelinux.org/aports/commit/?id=c87d40b7f9f1c9af7ceaf17ac9ce493589068c9b
- https://git.alpinelinux.org/aports/commit/?id=285bed6156d44aa6cb77dadf025fb3de4a9b8bb7
- https://git.alpinelinux.org/aports/commit/?id=367286011b41aab74ac1ac4cb44d3caa657f4d4e
- https://git.alpinelinux.org/aports/commit/?id=500e7d1decbdbbd24b5ad7327c83c556bf0d28f3