View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2018-10855 severity moderate: SUSE including 15 source package names (ansible, ansible-10-10.6.0-1.1, …), 20 product×package rows across 10 product lines (HPE Helion OpenStack 8, SUSE Linux Enterprise Server 11 SP3-TERADATA, … (10 product lines)): Fixed 15, Known Not Affected 5.
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.