cbcvebase.
CVE-2020-14332
published 2020-09-11

CVE-2020-14332: A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed…

PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.41%
32.9th percentile
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianansible< ansible 2.9.13+dfsg-1 (bookworm)ansible 2.9.13+dfsg-1 (bookworm)
debiandebian_linux
red_hatansible
red_hatansible
redhatansible>= 0 < 2.9.13+dfsg-12.9.13+dfsg-1
redhatansible>= 0 < 2.9.13+dfsg-12.9.13+dfsg-1
redhatansible>= 0 < 2.9.13+dfsg-12.9.13+dfsg-1
redhatansible>= 0 < 2.9.13+dfsg-12.9.13+dfsg-1
redhatansible>= 0 < 2.8.142.8.14
redhatansible>= 2.10.0a1 < 2.10.1rc22.10.1rc2
redhatansible>= 2.9.0a1 < 2.9.122.9.12
redhatansible_engine>= 2.8.0 < 2.8.142.8.14
redhatansible_engine>= 2.9.0 < 2.9.122.9.12

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.