PatchSiren

ansible-collections CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ansible-collections CVE published 2025-12-04

CVE-2025-14010

CVE-2025-14010 is an information disclosure issue in ansible-collection-community-general. When Ansible is run with verbose or debug output, plaintext passwords can be written to logs, which can then expose sensitive credentials to anyone with log access. The impact is confidentiality-focused and may include compromise of Keycloak accounts or administrative access if exposed secrets are reused.