CVE-2020-14332

Severity
5.5MEDIUM
EPSS
0.1%
top 64.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 11
Latest updateFeb 9

Description

A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDredhat/ansible_engine2.8.02.8.14+1
PyPIansible2.9.0a12.9.12+2
Debianansible< 2.9.13+dfsg-1+3
CVEListV5red_hat/ansible2.8.14, 2.9.12+1

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

4
GHSA
Insertion of Sensitive Information into Log File and Improper Output Neutralization for Logs in ansible2022-02-09
OSV
Insertion of Sensitive Information into Log File and Improper Output Neutralization for Logs in ansible2022-02-09
OSV
CVE-2020-14332: A flaw was found in the Ansible Engine when using module_args2020-09-11
CVEList
CVE-2020-14332: A flaw was found in the Ansible Engine when using module_args2020-09-11

📋Vendor Advisories

2
Red Hat
Ansible: module_args does not censor properly in --check mode2020-07-16
Debian
CVE-2020-14332: ansible - A flaw was found in the Ansible Engine when using module_args. Tasks executed wi...2020

💬Community

4
Bugzilla
CVE-2020-14332 ansible: module_args does not censor properly in --check mode [openstack-rdo]2020-07-22
Bugzilla
CVE-2020-14332 ansible: module_args does not censor properly in --check mode [fedora-all]2020-07-16
Bugzilla
CVE-2020-14332 Ansible: module_args does not censor properly in --check mode2020-07-16
Bugzilla
CVE-2020-14332 ansible: module_args does not censor properly in --check mode [epel-all]2020-07-16