Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
The product does not neutralize or incorrectly neutralizes output that is written to logs.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ansible | Redhat | 2.7.0 (including) | 2.7.15 (excluding) |
Ansible | Redhat | 2.8.0 (including) | 2.8.7 (excluding) |
Ansible | Redhat | 2.9.0 (including) | 2.9.1 (excluding) |
Ansible_tower | Redhat | 3.0 (including) | 3.0 (including) |
Ceph_storage | Redhat | 3.0 (including) | 3.0 (including) |
Cloudforms_management_engine | Redhat | 5.0 (including) | 5.0 (including) |
Red Hat Ansible Engine 2.7 for RHEL 7 | RedHat | ansible-0:2.7.15-1.el7ae | * |
Red Hat Ansible Engine 2.8 for RHEL 7 | RedHat | ansible-0:2.8.7-1.el7ae | * |
Red Hat Ansible Engine 2.8 for RHEL 8 | RedHat | ansible-0:2.8.7-1.el8ae | * |
Red Hat Ansible Engine 2.9 for RHEL 7 | RedHat | ansible-0:2.9.1-1.el7 | * |
Red Hat Ansible Engine 2.9 for RHEL 8 | RedHat | ansible-0:2.9.1-1.el8 | * |
Red Hat Ansible Engine 2 for RHEL 7 | RedHat | ansible-0:2.9.1-1.el7 | * |
Red Hat Ansible Engine 2 for RHEL 8 | RedHat | ansible-0:2.9.1-1.el8 | * |
Ansible | Ubuntu | disco | * |
Ansible | Ubuntu | eoan | * |
Ansible | Ubuntu | trusty | * |
Ansible | Ubuntu | upstream | * |
This can allow an attacker to forge log entries or inject malicious content into logs. Log forging vulnerabilities occur when: