A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2025-14010 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2418774 | Issue Tracking Vendor Advisory |
Configurations
History
No history.
Information
Published : 2025-12-04 10:16
Updated : 2026-01-02 20:41
NVD link : CVE-2025-14010
Mitre link : CVE-2025-14010
CVE.ORG link : CVE-2025-14010
JSON object : View
Products Affected
redhat
- community.general
CWE
CWE-532
Insertion of Sensitive Information into Log File
