Inclusion of Sensitive Information in Log Files in Red Hat Ansible Engine - CVE-2020-1753
Published: June 15, 2020
Vulnerability identifier: #VU29029
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1753
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to software stores sensitive information into log files when managing Kubernetes using the k8s connection plugin. A local user can read the log files and gain access to sensitive data.
Affected software
Red Hat Ansible Engine
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Proxy
SUSE Manager Proxy Module
SUSE Manager Retail Branch Server
SUSE Manager Client Tools for SLE Micro
SUSE Linux Enterprise Micro
Fedora
SUSE Linux Enterprise Server for SAP Applications
SUSE Manager Client Tools for SLE
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Package Hub 15
openSUSE Leap
openEuler
ansible (Debian package)
POS_Image-JeOS7
POS_Image-Graphical7
dracut-saltboot
golang-github-prometheus-promu
ansible
ansible-help
ansible (Red Hat package)
ansible-test
ansible-doc
python3-spacewalk-koan
spacewalk-koan
mgr-daemon
python3-uyuni-common-libs
uyuni-proxy-systemd-services
python3-spacewalk-client-setup
spacewalk-check
python3-spacewalk-client-tools
python3-spacewalk-check
spacewalk-client-setup
spacewalk-client-tools
spacecmd
grafana
grafana-debuginfo
Ansible
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Proxy
SUSE Manager Proxy Module
SUSE Manager Retail Branch Server
SUSE Manager Client Tools for SLE Micro
SUSE Linux Enterprise Micro
Fedora
SUSE Linux Enterprise Server for SAP Applications
SUSE Manager Client Tools for SLE
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Package Hub 15
openSUSE Leap
openEuler
ansible (Debian package)
POS_Image-JeOS7
POS_Image-Graphical7
dracut-saltboot
golang-github-prometheus-promu
ansible
ansible-help
ansible (Red Hat package)
ansible-test
ansible-doc
python3-spacewalk-koan
spacewalk-koan
mgr-daemon
python3-uyuni-common-libs
uyuni-proxy-systemd-services
python3-spacewalk-client-setup
spacewalk-check
python3-spacewalk-client-tools
python3-spacewalk-check
spacewalk-client-setup
spacewalk-client-tools
spacecmd
grafana
grafana-debuginfo
Ansible
How to mitigate CVE-2020-1753
Install updates from vendor's website.
Red Hat Ansible Engine - addressed in versions 2.7.17, 2.8.11, 2.9.7
ansible (Debian package) - update to 2.7.7+dfsg-1+deb10u1
POS_Image-JeOS7 - update to 0.1.1710765237.46af599-150000.1.21.2
POS_Image-Graphical7 - update to 0.1.1710765237.46af599-150000.1.21.2
dracut-saltboot - update to 0.1.1710765237.46af599-150000.1.53.2
golang-github-prometheus-promu - update to 0.14.0-150000.3.18.2
ansible - addressed in versions 2.5.5-2, 2.5.5-6
ansible-help - addressed in versions 2.5.5-2, 2.5.5-6
Ansible - addressed in versions 2.7.18-1.el7ae, 2.9.7-1.el7ae, 2.9.7-1.el8ae
ansible - addressed in versions 2.9.7-1.el7, 2.9.7-1.el8, 2.9.7-1.fc30, 2.9.7-1.fc31, 2.9.7-1.fc32
ansible (Red Hat package) - addressed in versions 2.9.7-1.el7ae, 2.9.7-1.el8ae
ansible - update to 2.9.27-150000.1.17.2
ansible-test - update to 2.9.27-150000.1.17.2
ansible-doc - update to 2.9.27-150000.1.17.2
python3-spacewalk-koan - update to 4.3.6-150000.3.33.2
spacewalk-koan - update to 4.3.6-150000.3.33.2
mgr-daemon - update to 4.3.9-150000.1.47.2
python3-uyuni-common-libs - update to 4.3.10-150000.1.39.2
uyuni-proxy-systemd-services - update to 4.3.12-150000.1.21.2
python3-spacewalk-client-setup - update to 4.3.19-150000.3.89.2
spacewalk-check - update to 4.3.19-150000.3.89.2
python3-spacewalk-client-tools - update to 4.3.19-150000.3.89.2
python3-spacewalk-check - update to 4.3.19-150000.3.89.2
spacewalk-client-setup - update to 4.3.19-150000.3.89.2
spacewalk-client-tools - update to 4.3.19-150000.3.89.2
spacecmd - update to 4.3.27-150000.3.116.2
grafana - update to 9.5.18-150000.1.63.2
grafana-debuginfo - update to 9.5.18-150000.1.63.2
ansible (Debian package) - update to 2.7.7+dfsg-1+deb10u1
POS_Image-JeOS7 - update to 0.1.1710765237.46af599-150000.1.21.2
POS_Image-Graphical7 - update to 0.1.1710765237.46af599-150000.1.21.2
dracut-saltboot - update to 0.1.1710765237.46af599-150000.1.53.2
golang-github-prometheus-promu - update to 0.14.0-150000.3.18.2
ansible - addressed in versions 2.5.5-2, 2.5.5-6
ansible-help - addressed in versions 2.5.5-2, 2.5.5-6
Ansible - addressed in versions 2.7.18-1.el7ae, 2.9.7-1.el7ae, 2.9.7-1.el8ae
ansible - addressed in versions 2.9.7-1.el7, 2.9.7-1.el8, 2.9.7-1.fc30, 2.9.7-1.fc31, 2.9.7-1.fc32
ansible (Red Hat package) - addressed in versions 2.9.7-1.el7ae, 2.9.7-1.el8ae
ansible - update to 2.9.27-150000.1.17.2
ansible-test - update to 2.9.27-150000.1.17.2
ansible-doc - update to 2.9.27-150000.1.17.2
python3-spacewalk-koan - update to 4.3.6-150000.3.33.2
spacewalk-koan - update to 4.3.6-150000.3.33.2
mgr-daemon - update to 4.3.9-150000.1.47.2
python3-uyuni-common-libs - update to 4.3.10-150000.1.39.2
uyuni-proxy-systemd-services - update to 4.3.12-150000.1.21.2
python3-spacewalk-client-setup - update to 4.3.19-150000.3.89.2
spacewalk-check - update to 4.3.19-150000.3.89.2
python3-spacewalk-client-tools - update to 4.3.19-150000.3.89.2
python3-spacewalk-check - update to 4.3.19-150000.3.89.2
spacewalk-client-setup - update to 4.3.19-150000.3.89.2
spacewalk-client-tools - update to 4.3.19-150000.3.89.2
spacecmd - update to 4.3.27-150000.3.116.2
grafana - update to 9.5.18-150000.1.63.2
grafana-debuginfo - update to 9.5.18-150000.1.63.2
External References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1753
- https://github.com/ansible-collections/kubernetes/pull/51
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DKPA4KC3OJSUFASUYMG66HKJE7ADNGFW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MRRYUU5ZBLPBXCYG6CFP35D64NP2UB2S/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WQVOQD4VAIXXTVQAJKTN7NUGTJFE2PCB/
- https://security.gentoo.org/glsa/202006-11
Related Security Bulletins
- Multiple vulnerabilities in Red Hat Ansible Engine
- Gentoo update for Ansible
- Debian update for ansible
- Ansible Engine 2 update for ansible
- Ansible Engine 2 update for ansible
- openEuler 20.03 LTS SP2 update for ansible
- openEuler 20.03 LTS SP1 update for ansible
- SUSE update for SUSE Manager Client Tools
- Red Hat update for Ansible engine
- Fedora 32 update for ansible
- Fedora 30 update for ansible
- Fedora 31 update for ansible
- Fedora EPEL 8 update for ansible
- Fedora EPEL 7 update for ansible