Input validation error - CVE-2020-14330

 

Input validation error - CVE-2020-14330

Published: September 11, 2020 / Updated: September 26, 2020


Vulnerability identifier: #VU47114
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14330
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to gain access to sensitive information.

An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed tasks to read keys used in playbooks from other users within the uri module. The highest threat from this vulnerability is to data confidentiality.


Affected software

SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Manager Proxy
SUSE Manager Proxy Module
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Manager Client Tools for SLE Micro
Fedora
SUSE Linux Enterprise Server for SAP Applications
SUSE Manager Client Tools for SLE
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Package Hub 15
openSUSE Leap
ansible (Debian package)
ansible (Alpine package)
ansible-base (Alpine package)
POS_Image-JeOS7
POS_Image-Graphical7
dracut-saltboot
golang-github-prometheus-promu
ansible
ansible-test
ansible-doc
spacewalk-koan
python3-spacewalk-koan
mgr-daemon
python3-uyuni-common-libs
uyuni-proxy-systemd-services
spacewalk-client-tools
spacewalk-client-setup
python3-spacewalk-check
python3-spacewalk-client-tools
spacewalk-check
python3-spacewalk-client-setup
spacecmd
grafana-debuginfo
grafana
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Data Computing Appliance (DCA)

How to mitigate CVE-2020-14330

Install update from vendor's website.

ansible (Debian package) - update to 2.7.7+dfsg-1+deb10u1
ansible (Alpine package) - update to 2.9.13-r0
ansible-base (Alpine package) - update to 2.10.2-r0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0
POS_Image-JeOS7 - update to 0.1.1710765237.46af599-150000.1.21.2
POS_Image-Graphical7 - update to 0.1.1710765237.46af599-150000.1.21.2
dracut-saltboot - update to 0.1.1710765237.46af599-150000.1.53.2
golang-github-prometheus-promu - update to 0.14.0-150000.3.18.2
ansible - addressed in versions 2.9.12-1.el8, 2.9.12-1.fc31, 2.9.12-1.fc32, 2.9.13-1.el8, 2.9.13-1.fc32
ansible - update to 2.9.27-150000.1.17.2
ansible-test - update to 2.9.27-150000.1.17.2
ansible-doc - update to 2.9.27-150000.1.17.2
spacewalk-koan - update to 4.3.6-150000.3.33.2
python3-spacewalk-koan - update to 4.3.6-150000.3.33.2
mgr-daemon - update to 4.3.9-150000.1.47.2
python3-uyuni-common-libs - update to 4.3.10-150000.1.39.2
uyuni-proxy-systemd-services - update to 4.3.12-150000.1.21.2
spacewalk-client-tools - update to 4.3.19-150000.3.89.2
spacewalk-client-setup - update to 4.3.19-150000.3.89.2
python3-spacewalk-check - update to 4.3.19-150000.3.89.2
python3-spacewalk-client-tools - update to 4.3.19-150000.3.89.2
spacewalk-check - update to 4.3.19-150000.3.89.2
python3-spacewalk-client-setup - update to 4.3.19-150000.3.89.2
spacecmd - update to 4.3.27-150000.3.116.2
grafana-debuginfo - update to 9.5.18-150000.1.63.2
grafana - update to 9.5.18-150000.1.63.2

External References

Related Security Bulletins