CVE-2018-10855

Description

Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
3.372

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2018-10855 are fixed in Python-ansible 2.4.5.0Windows
Vulnerabilities CVE-2018-10855 are fixed in Python-ansible 2.5.5Windows
ansible security update(DSA-4396-1) ansible_2.2.1.0-2+deb9u1_all.debLinux
Configuration management, deployment, and task execution system (USN-4072-1) ansible_2.0.0.2-2ubuntu1.3_all.debLinux
Configuration management, deployment, and task execution system (USN-4072-1) ansible_2.5.1+dfsg-1ubuntu0.1_all.debLinux
Configuration management, deployment, and task execution system (USN-4072-1) ansible_2.7.8+dfsg-1ubuntu0.19.04.1_all.debLinux
Vulnerabilities CVE-2018-10855 are fixed in Python-ansible for linux 2.4.5.0Linux
Vulnerabilities CVE-2018-10855 are fixed in Python-ansible for linux 2.5.5Linux
Insertion of Sensitive Information into Log File Vulnerability (CVE-2018-10855)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234