SB2021080802 - Information disclosure in Red Hat Ansible
Published: August 8, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use of insufficiently random values (CVE-ID: CVE-2020-10729)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to usegae of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as the template caching action for the same file since no re-evaluation happens.
Remediation
Install update from vendor's website.