Information disclosure in Ansible - CVE-2019-10217

 

Information disclosure in Ansible - CVE-2019-10217

Published: November 25, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU30582
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10217
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to gain access to sensitive information.

A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for all gcp modules is not setting no_log to True. Any sensitive data managed by that function would be leak as an output when running ansible playbooks.


Affected software

Ansible
ansible (Alpine package)
ansible
Fedora
SUSE Linux
Opensuse

How to mitigate CVE-2019-10217

Install update from vendor's website.

Ansible - addressed in versions 2.8.4, 2.8.4-1.el7ae, 2.8.4-1.el8ae
ansible (Alpine package) - update to 2.8.4-r0
ansible - addressed in versions 2.8.4-1.el7, 2.8.4-1.fc30

External References

Related Security Bulletins