In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| ansible(PyPI) | 0 | 2.6.20 | N/A |
| ansible(PyPI) | 2.7.0a1 | 2.7.14 | N/A |
| ansible(PyPI) | 2.8.0a1 | 2.8.6 | N/A |
CVSS Metrics