SB2021080802 - Information disclosure in Red Hat Ansible 



SB2021080802 - Information disclosure in Red Hat Ansible

Published: August 8, 2021

Security Bulletin ID SB2021080802
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Use of insufficiently random values (CVE-ID: CVE-2020-10729)

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to usegae of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as the template caching action for the same file since no re-evaluation happens.


Remediation

Install update from vendor's website.