In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "2.6.20"
},
{
"introduced": "2.7.0"
},
{
"fixed": "2.7.14"
},
{
"introduced": "2.8.0"
},
{
"fixed": "2.8.6"
},
{
"introduced": "0"
},
{
"last_affected": "2.8.0"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-14846.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0-sp1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "13"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.0"
}
]
}
]