Junglewise Threat Intelligence

CVE-2018-10855: PYSEC-2018-42 - Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used t

CVE-2018-10855 · Severity: low · CVSS 3.1 · Published 2018-07-03

Technologies: ansible (PyPI). Vendors: PyPI.

Executive brief

Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.

Affected products

  • PyPI ansible

Related threats