MEDIUM

CVE-2026-11819

Redhat Enterprise Linux 2026-06-23 CVSS v3.1
CVSS
5.5

Description

Module: plugins/modules/keyring_info.py

CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Issue: The module retrieves a passphrase from the OS native keyring (GNOME Keyring, macOS Keychain, Windows Credential Manager) and places it directly into result["passphrase"] with no output suppression, no no_log protection, and no documentation warning.

Root Cause:

Line 105 (protected): keyring_password=dict(type="str", required=True, no_log=True)
Line 127 (NOT protected): result["passphrase"] = passphrase

Observed Output:

{
"changed": false,
"passphrase": "MyMasterP@ssw0rd!SSH_Key_Secret"
}
Visible via register + debug:
{
"keyring_result": {
"changed": false,
"passphrase": "MyMasterP@ssw0rd!SSH_Key_Secret"
}
}

Impact:

Master passwords, SSH key passphrases and service credentials appear in all Ansible output

register: keyring_result followed by debug: var=keyring_result prints passphrase in full

Ansible fact caching backends (Redis, JSON file, memcached) may persist the passphrase

AWX/Tower job logs silently store the live credential

Fix:

module.exit_json(changed=False, passphrase=passphrase, _ansible_no_log=True)

Also add a documentation warning requiring callers to use no_log: true at the task level.

PoCs


Fig 1: PoC execution showing passphrase in plaintext output


Fig 2: Source code showing no_log=True on input (line 105) vs unprotected output (line 127)

Summary dbcve.org

The keyring_info.py Ansible module retrieves passphrases from OS native keyrings (GNOME Keyring, macOS Keychain, Windows Credential Manager) but outputs them in plaintext without no_log protection. While the input parameter (line 105) is correctly marked no_log=True, the output assignment at line 127 (`result['passphrase'] = passphrase`) exposes the sensitive credential in module return data.

Mitigation

Add `no_log=True` to the module.exit_json() call and update module documentation to warn users they must set no_log: true at the task level to prevent credential exposure in Ansible output, logs, and fact caching backends.

Weakness (CWE)

CWE-532 Sensitive Information in Logs

EPSS Score

0.16%
Probability of exploitation in next 30 days
5.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE