5.9

CVE-2018-10855

Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Ansible Engine Version >= 2.4 < 2.4.5
Redhat ≫ Ansible Engine Version > 2.5 <= 2.5.5
Redhat ≫ Ansible Engine Version 2.0
Redhat ≫ Cloudforms Version 4.6
Redhat ≫ Openstack Version 13
Redhat ≫ Virtualization Version 4.0
Debian ≫ Debian Linux Version 9.0
Redhat ≫ Openstack Version 10
Redhat ≫ Openstack Version 12
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.04
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.11% 0.865
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

https://access.redhat.com/errata/RHBA-2018:3788
Vendor Advisory
https://access.redhat.com/errata/RHSA-2018:2585
Vendor Advisory
https://access.redhat.com/errata/RHSA-2019:0054
Vendor Advisory
https://usn.ubuntu.com/4072-1/
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1948
Vendor Advisory
https://access.redhat.com/errata/RHSA-2018:1949
Vendor Advisory
https://access.redhat.com/errata/RHSA-2018:2022
Vendor Advisory
https://access.redhat.com/errata/RHSA-2018:2079
Vendor Advisory
https://access.redhat.com/errata/RHSA-2018:2184
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10855
Vendor Advisory
Issue Tracking
https://www.debian.org/security/2019/dsa-4396
Third Party Advisory