{"id":"UBUNTU-CVE-2019-10217","details":"A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for all gcp modules is not setting no_log to True. Any sensitive data managed by that function would be leak as an output when running ansible playbooks.","modified":"2025-07-16T07:39:13.375804Z","published":"2019-11-25T16:15:00Z","withdrawn":"2025-07-18T16:45:06Z","upstream":["CVE-2019-10217"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2019-10217"},{"type":"REPORT","url":"https://github.com/ansible/ansible/issues/56269"},{"type":"REPORT","url":"https://github.com/ansible/ansible/pull/59427"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2019-10217"}],"affected":[{"package":{"name":"ansible","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/ansible@2.8.6+dfsg-1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.8.6+dfsg-1"}]}],"versions":["2.8.3+dfsg-1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"ansible","binary_version":"2.8.6+dfsg-1"},{"binary_name":"ansible-doc","binary_version":"2.8.6+dfsg-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-10217.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"low"}]}