id: PYSEC-2019-4 details: In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process. affected: - package: name: ansible ecosystem: PyPI purl: pkg:pypi/ansible ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 2.6.20 - introduced: 2.7.0 - fixed: 2.7.14 - introduced: 2.8.0 - fixed: 2.8.6 versions: - "1.0" - "1.1" - "1.2" - 1.2.1 - 1.2.2 - 1.2.3 - 1.3.0 - 1.3.1 - 1.3.2 - 1.3.3 - 1.3.4 - "1.4" - 1.4.1 - 1.4.2 - 1.4.3 - 1.4.4 - 1.4.5 - "1.5" - 1.5.1 - 1.5.2 - 1.5.3 - 1.5.4 - 1.5.5 - "1.6" - 1.6.1 - 1.6.2 - 1.6.3 - 1.6.4 - 1.6.5 - 1.6.6 - 1.6.7 - 1.6.8 - 1.6.9 - 1.6.10 - "1.7" - 1.7.1 - 1.7.2 - "1.8" - 1.8.1 - 1.8.2 - 1.8.3 - 1.8.4 - 1.9.0 - 1.9.0.1 - 1.9.1 - 1.9.2 - 1.9.3 - 1.9.4 - 1.9.5 - 1.9.6 - 2.0.0.0 - 2.0.0 - 2.0.0.1 - 2.0.0.2 - 2.0.1.0 - 2.0.2.0 - 2.1.0.0 - 2.1.1.0 - 2.1.2.0 - 2.1.3.0 - 2.1.4.0 - 2.1.5.0 - 2.1.6.0 - 2.2.0.0 - 2.2.1.0 - 2.2.2.0 - 2.2.3.0 - 2.3.0.0 - 2.3.1.0 - 2.3.2.0 - 2.3.3.0 - 2.4.0.0 - 2.4.1.0 - 2.4.2.0 - 2.4.3.0 - 2.4.4.0 - 2.4.5.0 - 2.4.6.0 - 2.5.0a1 - 2.5.0b1 - 2.5.0b2 - 2.5.0rc1 - 2.5.0rc2 - 2.5.0rc3 - 2.5.0 - 2.5.1 - 2.5.2 - 2.5.3 - 2.5.4 - 2.5.5 - 2.5.6 - 2.5.7 - 2.5.8 - 2.5.9 - 2.5.10 - 2.5.11 - 2.5.12 - 2.5.13 - 2.5.14 - 2.5.15 - 2.6.0a1 - 2.6.0a2 - 2.6.0rc1 - 2.6.0rc2 - 2.6.0rc3 - 2.6.0rc4 - 2.6.0rc5 - 2.6.0 - 2.6.1 - 2.6.2 - 2.6.3 - 2.6.4 - 2.6.5 - 2.6.6 - 2.6.7 - 2.6.8 - 2.6.9 - 2.6.10 - 2.6.11 - 2.6.12 - 2.6.13 - 2.6.14 - 2.6.15 - 2.6.16 - 2.6.17 - 2.6.18 - 2.6.19 - 2.7.0 - 2.7.1 - 2.7.2 - 2.7.3 - 2.7.4 - 2.7.5 - 2.7.6 - 2.7.7 - 2.7.8 - 2.7.9 - 2.7.10 - 2.7.11 - 2.7.12 - 2.7.13 - 2.8.0 - 2.8.1 - 2.8.2 - 2.8.3 - 2.8.4 - 2.8.5 references: - type: REPORT url: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14846 - type: WEB url: https://github.com/ansible/ansible/pull/63366 - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2019:3207 - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2019:3201 - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2019:3202 - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2019:3203 - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2020:0756 - type: WEB url: http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.html - type: WEB url: http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.html - type: WEB url: https://lists.debian.org/debian-lts-announce/2020/05/msg00005.html - type: WEB url: https://lists.debian.org/debian-lts-announce/2021/01/msg00023.html - type: ADVISORY url: https://github.com/advisories/GHSA-pm48-cvv2-29q5 aliases: - CVE-2019-14846 - GHSA-pm48-cvv2-29q5 modified: "2021-03-26T22:15:00Z" published: "2019-10-08T19:15:00Z"