#VU47115 Inclusion of Sensitive Information in Log Files


Published: 2020-09-11 | Updated: 2020-09-26

Vulnerability identifier: #VU47115

Vulnerability risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2020-14332

CWE-ID: CWE-532

Exploitation vector: Local

Exploit availability: No

Description

The vulnerability allows a local authenticated user to gain access to sensitive information.

A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.

Mitigation
Install update from vendor's website.

External links
http://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14332
http://github.com/ansible/ansible/pull/71033


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability