CVE-2025-14010

A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:community.general:-:*:*:*:*:*:*:*

History

20 May 2026, 13:16

Type Values Removed Values Added
References () https://github.com/ansible-collections/community.general/issues/11000 - () https://github.com/ansible-collections/community.general/issues/11000 -

06 May 2026, 17:16

Type Values Removed Values Added
References
  • () https://github.com/ansible-collections/community.general/issues/11000 -
  • () https://github.com/ansible-collections/community.general/pull/11005 -
  • () https://github.com/ansible-community/ansible-build-data/blob/main/12/CHANGELOG-v12.md#security-fixes -

02 Jan 2026, 20:41

Type Values Removed Values Added
First Time Redhat
Redhat community.general
References () https://access.redhat.com/security/cve/CVE-2025-14010 - () https://access.redhat.com/security/cve/CVE-2025-14010 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2418774 - () https://bugzilla.redhat.com/show_bug.cgi?id=2418774 - Issue Tracking, Vendor Advisory
CPE cpe:2.3:a:redhat:community.general:-:*:*:*:*:*:*:*

23 Dec 2025, 15:15

Type Values Removed Values Added
CWE CWE-532

04 Dec 2025, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-04 10:16

Updated : 2026-05-20 13:16


NVD link : CVE-2025-14010

Mitre link : CVE-2025-14010

CVE.ORG link : CVE-2025-14010


JSON object : View

Products Affected

redhat

  • community.general
CWE
CWE-532

Insertion of Sensitive Information into Log File