SB2020092609 - Inclusion of Sensitive Information in Log Files in ansible (Alpine package)



SB2020092609 - Inclusion of Sensitive Information in Log Files in ansible (Alpine package)

Published: September 26, 2020

Security Bulletin ID SB2020092609
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2020-14332)

The vulnerability allows a local authenticated user to gain access to sensitive information.

A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.


Remediation

Install update from vendor's website.