CVE-2019-14846: Debian Linux
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
- Opensuse Backports Sle: version 15.0 only
- Opensuse Leap: version 15.1 only
- Red Hat Ansible Engine: before 2.6.20 (fixed in 2.6.20); from 2.7.0, before 2.7.14 (fixed in 2.7.14); from 2.8.0, before 2.8.6 (fixed in 2.8.6); version 2.0 only; version 2.8.0 only
- Red Hat Openstack: version 13 only
Published 2019-10-08. Last modified 2026-06-17.