A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2025-14010 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2418774 | Issue Tracking Vendor Advisory |
Configurations
History
02 Jan 2026, 20:41
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Redhat
Redhat community.general |
|
| References | () https://access.redhat.com/security/cve/CVE-2025-14010 - Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2418774 - Issue Tracking, Vendor Advisory | |
| CPE | cpe:2.3:a:redhat:community.general:-:*:*:*:*:*:*:* |
23 Dec 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-532 |
04 Dec 2025, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-04 10:16
Updated : 2026-01-02 20:41
NVD link : CVE-2025-14010
Mitre link : CVE-2025-14010
CVE.ORG link : CVE-2025-14010
JSON object : View
Products Affected
redhat
- community.general
CWE
CWE-532
Insertion of Sensitive Information into Log File
