Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21701
HistoryOct 15, 2019 - 5:28 a.m.

Information Disclosure

2019-10-1505:28:28
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.0005 Low

EPSS

Percentile

17.2%

ansible is vulnerable to information disclosure. The attack exists when an incorrect parameter name is passed to a module having an argument_spec with sub parameters marked as no_log, causing a failure of the task. It exposes data in sub parameter fields as it leaves the data unmasked if it is run with increased verbosity and present in the module invocation arguments for the task.