#VU47115 Inclusion of Sensitive Information in Log Files - CVE-2020-14332

 

#VU47115 Inclusion of Sensitive Information in Log Files - CVE-2020-14332

Published: September 11, 2020 / Updated: September 26, 2020


Vulnerability identifier: #VU47115
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-14332
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Software vendor:

Description

The vulnerability allows a local authenticated user to gain access to sensitive information.

A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.


Remediation

Install update from vendor's website.

External links