Vulnerabilities > Redhat > Ansible Engine > 2.7.9

DATE CVE VULNERABILITY TITLE RISK
2019-10-14 CVE-2019-14858 Information Exposure Through Log Files vulnerability in Redhat Ansible Engine
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5.
local
low complexity
redhat CWE-532
2.1
2019-10-08 CVE-2019-14846 Improper Output Neutralization for Logs vulnerability in multiple products
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level.
local
low complexity
redhat debian opensuse CWE-117
2.1
2018-11-29 CVE-2018-16859 Information Exposure Through Log Files vulnerability in Redhat Ansible Engine
Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext.
local
low complexity
redhat CWE-532
2.1