CVE-2020-1746

Severity
5.0MEDIUM
EPSS
0.1%
top 81.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 12
Latest updateApr 20

Description

A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when the ldap_attr and ldap_entry community modules are used. The issue discloses the LDAP bind password to stdout or a log file if a playbook task is written using the bind_pw in the parameters field. The highest threat from this vulnerability is data confidentiality.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:NExploitability: 1.3 | Impact: 3.6

Affected Packages5 packages

NVDredhat/ansible_engine2.7.02.7.17+2
NVDredhat/ansible_tower3.4.03.4.5+2
PyPIansible2.8.0a12.8.11+2
Debianansible< 2.9.7+dfsg-1+3
CVEListV5red_hat/ansible6 versions+5

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

4
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in ansible2021-04-20
OSV
Exposure of Sensitive Information to an Unauthorized Actor in ansible2021-04-20
OSV
CVE-2020-1746: A flaw was found in the Ansible Engine affecting Ansible Engine versions 22020-05-12
CVEList
CVE-2020-1746: A flaw was found in the Ansible Engine affecting Ansible Engine versions 22020-05-12

📋Vendor Advisories

2
Red Hat
ansible: Information disclosure issue in ldap_attr and ldap_entry modules2020-02-28
Debian
CVE-2020-1746: ansible - A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x b...2020

💬Community

4
Bugzilla
CVE-2020-1746 ansible: Information disclosure issue in ldap_attr and ldap_entry modules [fedora-all]2020-02-28
Bugzilla
CVE-2020-1746 ansible: Information disclosure issue in ldap_attr and ldap_entry modules [openstack-rdo]2020-02-28
Bugzilla
CVE-2020-1746 ansible: Information disclosure issue in ldap_attr and ldap_entry modules [epel-all]2020-02-28
Bugzilla
CVE-2020-1746 ansible: Information disclosure issue in ldap_attr and ldap_entry modules2020-02-20