Information disclosure in Ansible and Ansible Tower - CVE-2020-1746
Published: July 7, 2020
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to Ansible discloses the LDAP bind password to stdout or a log file if a playbook task is written using the bind_pw in the parameters field. A local user can gain unauthorized access to sensitive information on the system.
Successful exploitation of vulnerability requires that the ldap_attr and ldap_entry community modules are used.
Affected software
Ansible Tower
Red Hat Ansible Engine
ansible (Debian package)
ansible (Alpine package)
ansible
ansible (Red Hat package)
Fedora
How to mitigate CVE-2020-1746
Ansible Tower - addressed in versions 3.5.6, 3.6.4
ansible (Debian package) - update to 2.7.7+dfsg-1+deb10u1
ansible (Alpine package) - update to 2.7.17-r0
ansible - addressed in versions 2.9.7-1.el7, 2.9.7-1.el8, 2.9.7-1.fc30, 2.9.7-1.fc31, 2.9.7-1.fc32
ansible (Red Hat package) - addressed in versions 2.9.7-1.el7ae, 2.9.7-1.el8ae
External References
Related Security Bulletins
- Information disclosure in Ansible Engine and Ansible Tower
- Information disclosure in ansible (Alpine package)
- Debian update for ansible
- Ansible Engine 2 update for ansible
- Ansible Engine 2 update for ansible
- Ansible Engine 2 update for ansible
- Red Hat update for Ansible engine
- Fedora 32 update for ansible
- Fedora 30 update for ansible
- Fedora 31 update for ansible
- Fedora EPEL 8 update for ansible
- Fedora EPEL 7 update for ansible