CVE-2019-14858
Last modified
CVE-2019-14858 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields will not be masked and will be displayed if Ansible is run with increased verbosity and present in the module invocation arguments for the task.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Ansible Engine | >= 2.0, <= 2.8.0 |
| Redhat | Ansible Tower | >= 3.0, <= 3.5.0 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14858Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14858Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-14858?
How severe is CVE-2019-14858?
How do I fix CVE-2019-14858?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-14852A flaw was found in 3scale’s APIcast gateway that enabled th…7.5
- CVE-2019-14853An error-handling flaw was found in python-ecdsa before vers…7.5
- CVE-2019-14854OpenShift Container Platform 4 does not sanitize secret data…6.5
- CVE-2019-14855A flaw was found in the way certificate signatures could be …7.5
- CVE-2019-14856ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable …6.5
- CVE-2019-14857A flaw was found in mod_auth_openidc before version 2.4.0.1.…6.1
- CVE-2019-14859A flaw was found in all python-ecdsa versions before 0.13.3,…9.1
- CVE-2019-1486A spoofing vulnerability exists in Visual Studio Live Share …6.1
- CVE-2019-14860It was found that the Syndesis configuration for Cross-Origi…6.5
- CVE-2019-14861All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.1…5.3
- CVE-2019-14862There is a vulnerability in knockout before version 3.5.0-be…6.1
- CVE-2019-14863There is a vulnerability in all angular versions before 1.5.…6.1
Are you affected by CVE-2019-14858?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
