Vulnerability CVE-2020-14332: Information

Description

A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.

Severity: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Published: Sept. 11, 2020
Modified: Nov. 7, 2023
Error type identifier: CWE-117

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
ansiblep102.9.13-alt12.9.27-alt3.p10.2ALT-PU-2020-2923-1259006Fixed
ansiblep92.9.13-alt12.9.27-alt1ALT-PU-2020-3006-1259265Fixed
ansiblec10f12.9.13-alt12.9.27-alt3.p10.1ALT-PU-2020-2923-1259006Fixed
ansiblec9f22.9.21-alt12.9.26-alt2ALT-PU-2021-1800-1271383Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://github.com/ansible/ansible/pull/71033
  • Patch
  • Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14332
  • Issue Tracking
  • Vendor Advisory
DSA-4950
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:*
      Start including
      2.8.0
      End excliding
      2.8.14

      cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:*
      Start including
      2.9.0
      End excliding
      2.9.12

      Configuration 2

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*