Total vulnerabilities in the database
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.
Software | From | Fixed in |
---|---|---|
redhat / virtualization | 4.0 | 4.0.x |
redhat / cloudforms | 4.6 | 4.6.x |
redhat / ansible_engine | 2.0 | 2.0.x |
redhat / ansible_engine | 2.5.x | 2.5.5.x |
redhat / ansible_engine | 2.4 | 2.4.5 |
redhat / openstack | 13 | 13.x |
debian / debian_linux | 9.0 | 9.0.x |
redhat / openstack | 10 | 10.x |
redhat / openstack | 12 | 12.x |
canonical / ubuntu_linux | 16.04 | 16.04.x |
canonical / ubuntu_linux | 18.04 | 18.04.x |
canonical / ubuntu_linux | 19.04 | 19.04.x |
![]() |
2.5.0 | 2.5.5 |
![]() |
2.4.0 | 2.4.5 |