Lucene search

K
redhatcveRedhat.comRH:CVE-2019-10217
HistoryOct 09, 2019 - 6:23 a.m.

CVE-2019-10217

2019-10-0906:23:15
redhat.com
access.redhat.com
13

0.002 Low

EPSS

Percentile

56.3%

A flaw was found in the gcp module of ansible. Certain fields managing sensitive data should be marked by the no_log feature. The service_account_contents(), which is common class for all gcp modules, is not being set as no_log to True. Any sensitive data managed by that function would be leaked as an output when running ansible playbooks. Data confidentiality is the highest threat with this vulnerability.