CVE-2025-14010: Ansible-collection-community-general: ansible-collection-community-general: keycloak user module leaks credentials in verbose output
A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14010?
CVE-2025-14010 has a medium severity rating as it allows for information exposure of sensitive credentials.
How do I fix CVE-2025-14010?
To fix CVE-2025-14010, update to the latest version of the ansible-collection-community-general that addresses this vulnerability.
What kind of data is exposed by CVE-2025-14010?
CVE-2025-14010 can expose sensitive information, specifically plaintext passwords, through verbose output.
Who is affected by CVE-2025-14010?
Users of the ansible-collection-community-general who run Ansible in debug modes are affected by CVE-2025-14010.
What should I do if I have logged sensitive information due to CVE-2025-14010?
If sensitive information was logged due to CVE-2025-14010, ensure to rotate any exposed credentials immediately.