Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6828
HistoryJun 20, 2018 - 7:26 a.m.

Information Disclosure

2018-06-2007:26:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.003 Low

EPSS

Percentile

71.9%

ansible is vulnerable to information disclosure. The application doesn’t properly enforce the no_log flag, meaning that sensitive information that has been passed to the task will be logged by the system. This allows a malicious user with access to the logs can gain access to this sensitive information.

CPENameOperatorVersion
ansiblele2.4.4.0
ansiblele2.6.0rc2
ansiblele2.5.4