CVE detail
CVE-2025-14010 — CVE-2025-14010
Published 2025-12-04 · Modified 2026-06-17 · Vendor redhat · Product community.general · Source nvd
MEDIUM
severity
CVSS-derived band
0.0013
EPSS probability
exploitation probability, 30d
3.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References