Inclusion of Sensitive Information in Log Files - CVE-2020-14332

 

Inclusion of Sensitive Information in Log Files - CVE-2020-14332

Published: September 11, 2020 / Updated: September 26, 2020


Vulnerability identifier: #VU47115
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14332
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to gain access to sensitive information.

A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.


Affected software

SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Proxy Module
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Manager Client Tools for SLE Micro
Fedora
SUSE Linux Enterprise Server for SAP Applications
SUSE Manager Client Tools for SLE
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Package Hub 15
openSUSE Leap
ansible (Debian package)
ansible (Alpine package)
ansible-base (Alpine package)
POS_Image-JeOS7
POS_Image-Graphical7
dracut-saltboot
golang-github-prometheus-promu
ansible
ansible-test
ansible-doc
spacewalk-koan
python3-spacewalk-koan
mgr-daemon
python3-uyuni-common-libs
uyuni-proxy-systemd-services
spacewalk-client-setup
python3-spacewalk-check
python3-spacewalk-client-tools
spacewalk-check
spacewalk-client-tools
python3-spacewalk-client-setup
spacecmd
grafana-debuginfo
grafana
Data Computing Appliance (DCA)

How to mitigate CVE-2020-14332

Install update from vendor's website.

ansible (Debian package) - update to 2.7.7+dfsg-1+deb10u1
ansible (Alpine package) - update to 2.9.13-r0
ansible-base (Alpine package) - update to 2.10.2-r0
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0
POS_Image-JeOS7 - update to 0.1.1710765237.46af599-150000.1.21.2
POS_Image-Graphical7 - update to 0.1.1710765237.46af599-150000.1.21.2
dracut-saltboot - update to 0.1.1710765237.46af599-150000.1.53.2
golang-github-prometheus-promu - update to 0.14.0-150000.3.18.2
ansible - addressed in versions 2.9.12-1.el8, 2.9.12-1.fc31, 2.9.12-1.fc32, 2.9.13-1.el8, 2.9.13-1.fc32
ansible - update to 2.9.27-150000.1.17.2
ansible-test - update to 2.9.27-150000.1.17.2
ansible-doc - update to 2.9.27-150000.1.17.2
spacewalk-koan - update to 4.3.6-150000.3.33.2
python3-spacewalk-koan - update to 4.3.6-150000.3.33.2
mgr-daemon - update to 4.3.9-150000.1.47.2
python3-uyuni-common-libs - update to 4.3.10-150000.1.39.2
uyuni-proxy-systemd-services - update to 4.3.12-150000.1.21.2
spacewalk-client-setup - update to 4.3.19-150000.3.89.2
python3-spacewalk-check - update to 4.3.19-150000.3.89.2
python3-spacewalk-client-tools - update to 4.3.19-150000.3.89.2
spacewalk-check - update to 4.3.19-150000.3.89.2
spacewalk-client-tools - update to 4.3.19-150000.3.89.2
python3-spacewalk-client-setup - update to 4.3.19-150000.3.89.2
spacecmd - update to 4.3.27-150000.3.116.2
grafana-debuginfo - update to 9.5.18-150000.1.63.2
grafana - update to 9.5.18-150000.1.63.2

External References

Related Security Bulletins