Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-14330

Опубликовано: 11 сент. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.1
CVSS3: 5

Описание

An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed tasks to read keys used in playbooks from other users within the uri module. The highest threat from this vulnerability is to data confidentiality.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

11.1.0+dfsg-1
eoan

ignored

end of life
esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/jammy

not-affected

2.10.7+merged+base+2.10.8+dfsg-1ubuntu0.1~esm4
esm-apps/noble

not-affected

9.2.0+dfsg-0ubuntu5
esm-apps/xenial

needed

esm-infra-legacy/trusty

ignored

changes too intrusive
focal

ignored

end of standard support, was needed

Показывать по

EPSS

Процентиль: 33%
0.00133
Низкий

2.1 Low

CVSS2

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
redhat
почти 6 лет назад

An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed tasks to read keys used in playbooks from other users within the uri module. The highest threat from this vulnerability is to data confidentiality.

CVSS3: 5
nvd
больше 5 лет назад

An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed tasks to read keys used in playbooks from other users within the uri module. The highest threat from this vulnerability is to data confidentiality.

CVSS3: 5
debian
больше 5 лет назад

An Improper Output Neutralization for Logs flaw was found in Ansible w ...

CVSS3: 5.5
github
почти 4 года назад

Improper Output Neutralization and Improper Encoding or Escaping of Output for Logs in ansible

CVSS3: 5.5
fstec
больше 5 лет назад

Уязвимость модуля URI системы управления конфигурациями Ansible, связанная с недостатком механизма кодирование или экранирование выходных данных, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 33%
0.00133
Низкий

2.1 Low

CVSS2

5 Medium

CVSS3