GHSA-h653-95qw-h2mp · Severity: medium · Ecosystem: pip — Ansible leaks sensitive information to logs when told not to
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields will not be masked and will be displayed if Ansible is run with increased verbosity and present in the module invocation arguments for the task.
Conclusion & alert: CVE-2019-14858 is rated Low Risk (30.2/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.08%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-01 | 0.04% | 0.08% | +0.04% |
| 2 | 2026-04-21 | 0.06% | 0.04% | -0.02% |
| 3 | 2026-01-06 | — | 0.06% | — |
Full EPSS history (16 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.5 | 3.1 | MEDIUM |
|
1.8 | 3.6 | [email protected] |
| 7.3 | 3.0 | HIGH |
|
1.3 | 5.9 | [email protected] |
| 2.1 | 2.0 | LOW |
|
3.9 | 2.9 | [email protected] |
GHSA-h653-95qw-h2mp · Severity: medium · Ecosystem: pip — Ansible leaks sensitive information to logs when told not to
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
medium | CVE-2019-14858: 2 source package rows (ansible, ansible-base); 5 state rows across 5 repos (3.10-main, 3.11-main, 3.12-main, edge-community, edge-main); fixed 5, open 0. | https://security.alpinelinux.org/vuln/CVE-2019-14858 |
debian
|
not yet assigned | CVE-2019-14858 not yet assigned priority: Debian including 1 source packages (ansible), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2019-14858 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2019-14858 |
suse
|
low | CVE-2019-14858 severity low: SUSE including 119 source package names (ansible-10-10.6.0-1.1, ansible-11-11.11.0-1.1, …), 250 product×package rows across 10 product lines (HPE Helion OpenStack 8, HPE Helion OpenStack Cloud 8, … (10 product lines)): Fixed 246, Known Not Affected 4. | https://www.suse.com/security/cve/CVE-2019-14858/ |
ubuntu
|
low | CVE-2019-14858 low priority: Ubuntu including 1 source packages (ansible), 18 status rows across 18 suites (bionic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): not-affected 14, ignored 2, needed 1, released 1. | https://ubuntu.com/security/CVE-2019-14858 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| redhat | ansible_engine | >= 2.0, <= 2.8.0 | cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:* |
| redhat | ansible_tower | >= 3.0, <= 3.5.0 | cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:* |