CVE-2025-14010

A

flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:community.general:-:*:*:*:*:*:*:*

History

02 Jan 2026, 20:41

Type Values Removed Values Added
CPE cpe:2.3:a:redhat:community.general:-:*:*:*:*:*:*:*
References () https://access.redhat.com/security/cve/CVE-2025-14010 - () https://access.redhat.com/security/cve/CVE-2025-14010 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2418774 - () https://bugzilla.redhat.com/show_bug.cgi?id=2418774 - Issue Tracking, Vendor Advisory
First Time Redhat
Redhat community.general

23 Dec 2025, 15:15

Type Values Removed Values Added
CWE CWE-532

04 Dec 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-04 10:16

Updated : 2026-01-02 20:41


NVD link : CVE-2025-14010

Mitre link : CVE-2025-14010

CVE.ORG link : CVE-2025-14010


JSON object : View

Products Affected
CWE
CWE-532

Insertion of Sensitive Information into Log File