Information disclosure in Ansible - CVE-2020-1739

 

Information disclosure in Ansible - CVE-2020-1739

Published: July 7, 2020


Vulnerability identifier: #VU29564
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1739
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to password being exposed to local users when a password is set with the argument "password" of svn module. A local user can read the cmdline file from that particular PID on the procfs and obtain the password.


Affected software

Ansible
Red Hat Ansible Engine
ansible (Debian package)
ansible (Alpine package)
ansible-help
ansible
ansible (Red Hat package)
Fedora
openEuler

How to mitigate CVE-2020-1739

Install updates from vendor's website.

Ansible - addressed in versions 2.7.17, 2.8.8, 2.9.5, 2.7.17-1.el7ae, 2.8.11-1.el7ae, 2.8.11-1.el8ae, 2.9.7-1.el7ae, 2.9.7-1.el8ae
ansible (Debian package) - update to 2.7.7+dfsg-1+deb10u1
ansible (Alpine package) - update to 2.7.17-r0
ansible-help - addressed in versions 2.5.5-2, 2.5.5-6
ansible - addressed in versions 2.5.5-2, 2.5.5-6
ansible - addressed in versions 2.9.6-1.el7, 2.9.6-1.el8, 2.9.6-1.fc30, 2.9.6-1.fc31, 2.9.6-1.fc32, 2.9.7-1.el8
ansible (Red Hat package) - addressed in versions 2.9.7-1.el7ae, 2.9.7-1.el8ae

External References

Related Security Bulletins