Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-14332

Опубликовано: 11 сент. 2020
Источник: debian
EPSS Низкий

Описание

A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ansiblefixed2.9.13+dfsg-1package
ansibleend-of-lifestretchpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1857805

  • https://github.com/ansible/ansible/pull/71033

  • https://github.com/ansible/ansible/commit/6cae9a4b168df776bf82deb04b2c62e00c38b49a (v2.9.12)

EPSS

Процентиль: 36%
0.00149
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 5 лет назад

A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.5
redhat
больше 5 лет назад

A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.5
nvd
больше 5 лет назад

A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.5
github
почти 4 года назад

Insertion of Sensitive Information into Log File and Improper Output Neutralization for Logs in ansible

CVSS3: 5.5
fstec
больше 5 лет назад

Уязвимость системы управления конфигурациями Ansible, связанная с неправильной обработкой выходных данных для журналов регистрации, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 36%
0.00149
Низкий