CVE-2020-14332
published 2020-09-11CVE-2020-14332: A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.41%
32.9th percentile
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 2.9.13+dfsg-1 (bookworm) | ansible 2.9.13+dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| redhat | ansible | >= 0 < 2.9.13+dfsg-1 | 2.9.13+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.13+dfsg-1 | 2.9.13+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.13+dfsg-1 | 2.9.13+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.13+dfsg-1 | 2.9.13+dfsg-1 |
| redhat | ansible | >= 0 < 2.8.14 | 2.8.14 |
| redhat | ansible | >= 2.10.0a1 < 2.10.1rc2 | 2.10.1rc2 |
| redhat | ansible | >= 2.9.0a1 < 2.9.12 | 2.9.12 |
| redhat | ansible_engine | >= 2.8.0 < 2.8.14 | 2.8.14 |
| redhat | ansible_engine | >= 2.9.0 < 2.9.12 | 2.9.12 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Insertion of Sensitive Information into Log File and Improper Output Neutralization for Logs in ansible
ghsa·2022-02-09
CVE-2020-14332 [MEDIUM] CWE-117 Insertion of Sensitive Information into Log File and Improper Output Neutralization for Logs in ansible
Insertion of Sensitive Information into Log File and Improper Output Neutralization for Logs in ansible
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.
OSV
Insertion of Sensitive Information into Log File and Improper Output Neutralization for Logs in ansible
osv·2022-02-09
CVE-2020-14332 [MEDIUM] Insertion of Sensitive Information into Log File and Improper Output Neutralization for Logs in ansible
Insertion of Sensitive Information into Log File and Improper Output Neutralization for Logs in ansible
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.
OSV
CVE-2020-14332: A flaw was found in the Ansible Engine when using module_args
osv·2020-09-11·CVSS 5.5
CVE-2020-14332 [MEDIUM] CVE-2020-14332: A flaw was found in the Ansible Engine when using module_args
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.
Red Hat
Ansible: module_args does not censor properly in --check mode
vendor_redhat·2020-07-16·CVSS 5.5
CVE-2020-14332 [MEDIUM] CWE-215 Ansible: module_args does not censor properly in --check mode
Ansible: module_args does not censor properly in --check mode
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.
Statement: The version of ansible provided in Red Hat Gluster Storage 3, Red Hat Ceph Storage 2 and 3 does not contain the vulnerable fun
Debian
CVE-2020-14332: ansible - A flaw was found in the Ansible Engine when using module_args. Tasks executed wi...
vendor_debian·2020·CVSS 5.5
CVE-2020-14332 [MEDIUM] CVE-2020-14332: ansible - A flaw was found in the Ansible Engine when using module_args. Tasks executed wi...
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.
Scope: local
bookworm: resolved (fixed in 2.9.13+dfsg-1)
bullseye: resolved (fixed in 2.9.13+dfsg-1)
forky: resolved (fixed in 2.9.13+dfsg-1)
sid: resolved (fixed in 2.9.13+dfsg-1)
trixie: resolved (fixed in 2.9.13+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14332 ansible: module_args does not censor properly in --check mode [openstack-rdo]
bugzilla·2020-07-22·CVSS 5.5
CVE-2020-14332 [MEDIUM] CVE-2020-14332 ansible: module_args does not censor properly in --check mode [openstack-rdo]
CVE-2020-14332 ansible: module_args does not censor properly in --check mode [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
RDO includes openstac
Bugzilla
CVE-2020-14332 ansible: module_args does not censor properly in --check mode [fedora-all]
bugzilla·2020-07-16·CVSS 5.5
CVE-2020-14332 [MEDIUM] CVE-2020-14332 ansible: module_args does not censor properly in --check mode [fedora-all]
CVE-2020-14332 ansible: module_args does not censor properly in --check mode [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2020-14332 Ansible: module_args does not censor properly in --check mode
bugzilla·2020-07-16·CVSS 5.5
CVE-2020-14332 [MEDIUM] CVE-2020-14332 Ansible: module_args does not censor properly in --check mode
CVE-2020-14332 Ansible: module_args does not censor properly in --check mode
module_args is not censored properly when using the check mode. This only happens using -vvv on the CLI, but in AWX/Tower it does not matter what verbosity setting is used, because it is saved in the event data regardless. So sensitive data is exposed allowing unauthorized users accessing to it.
Discussion:
Created ansible tracking bugs for this issue:
Affects: epel-all [bug 1857817]
Affects: fedora-all [bug 1857818]
---
Created ansible tracking bugs for this issue:
Affects: openstack-rdo [bug 1859535]
---
Upstream Fix:
https://github.com/ansible/ansible/pull/71033
---
Statement:
The version of ansible provided in Red Hat Gluster Storage 3, Red Hat Ceph Storage 2 and 3 does not contain the vulnerable
Bugzilla
CVE-2020-14332 ansible: module_args does not censor properly in --check mode [epel-all]
bugzilla·2020-07-16·CVSS 5.5
CVE-2020-14332 [MEDIUM] CVE-2020-14332 ansible: module_args does not censor properly in --check mode [epel-all]
CVE-2020-14332 ansible: module_args does not censor properly in --check mode [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
2020-09-11
Published