SB2020092609 - Inclusion of Sensitive Information in Log Files in ansible (Alpine package)
Published: September 26, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2020-14332)
The vulnerability allows a local authenticated user to gain access to sensitive information.
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.
Remediation
Install update from vendor's website.