#VU29022 Exposure of Resource to Wrong Sphere in Red Hat Ansible Engine and Ansible Tower - CVE-2020-10685
Published: June 15, 2020
Red Hat Ansible Engine
Ansible Tower
Red Hat Inc.
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists in Ansible Engine when using modules which decrypts vault files such as "assemble", "script", "unarchive", "win_copy", "aws_s3" or "copy modules". A local user can gain unathorized access to sensitive information on the target system.