Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12647
HistoryJan 15, 2019 - 9:20 a.m.

Information Disclosure

2019-01-1509:20:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.003 Low

EPSS

Percentile

71.9%

ansible is vulnerable to information disclosure. The application doesn’t properly enforce the no_log flag, meaning that sensitive information that has been passed to the task will be logged by the system. This allows a malicious user with access to the logs can gain access to this sensitive information.