#VU29566 Information disclosure in Ansible and Ansible Tower - CVE-2020-1746
Published: July 7, 2020
Ansible
Ansible Tower
Red Hat Inc.
Description
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to Ansible discloses the LDAP bind password to stdout or a log file if a playbook task is written using the bind_pw in the parameters field. A local user can gain unauthorized access to sensitive information on the system.
Successful exploitation of vulnerability requires that the ldap_attr and ldap_entry community modules are used.