CVE Vulnerabilities

CVE-2025-14010

Insertion of Sensitive Information into Log File

Published: Dec 04, 2025 | Modified: Jan 02, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM

A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Community.general Redhat - (including) - (including)

Potential Mitigations

References