CVE-2020-14332: Medium severity red hat ansible engine vulnerability
A flaw was found in the Ansible Engine when using moduleargs. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.
Other sources
moduleargs is not censored properly when using the check mode. This only happens using -vvv on the CLI, but in AWX/Tower it does not matter what verbosity setting is used, because it is saved in the event data regardless. So sensitive data is exposed allowing unauthorized users accessing to it.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-14332?
CVE-2020-14332 is a vulnerability found in Ansible Engine when using module_args, allowing unauthorized users to read sensitive data.
How does CVE-2020-14332 impact confidentiality?
CVE-2020-14332 poses a threat to confidentiality, as unauthorized users can exploit this vulnerability to access sensitive data.
What is the severity level of CVE-2020-14332?
The severity level of CVE-2020-14332 is medium with a CVSS score of 5.5.
Which software versions are affected by CVE-2020-14332?
Ansible Engine versions up to 2.9.12 and 2.8.14, as well as Redhat Ansible Engine versions 2.8.0 to 2.8.14 and 2.9.0 to 2.9.12 are affected by CVE-2020-14332.
How can I fix CVE-2020-14332?
To fix CVE-2020-14332, update Ansible Engine to version 2.9.12 or Redhat Ansible Engine to version 2.8.14.