CVE-2020-14332: Medium severity red hat ansible engine vulnerability

Published Jul 16, 2020
·
Updated

A flaw was found in the Ansible Engine when using moduleargs. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.

Other sources

moduleargs is not censored properly when using the check mode. This only happens using -vvv on the CLI, but in AWX/Tower it does not matter what verbosity setting is used, because it is saved in the event data regardless. So sensitive data is exposed allowing unauthorized users accessing to it.

Affected Software

9 affected componentsFixes available
redhat/ansible-engine<2.9.12
2.9.12
redhat/ansible-engine<2.8.14
2.8.14
debian/ansible
2.7.7+dfsg-1+deb10u12.7.7+dfsg-1+deb10u22.10.7+merged+base+2.10.8+dfsg-17.3.0+dfsg-17.7.0+dfsg-3
pip/ansible>=2.10.0a1<2.10.1rc2
2.10.1rc2
pip/ansible>=2.9.0a1<2.9.12
2.9.12
pip/ansible<2.8.14
2.8.14
redhat Ansible Engine>=2.8.0<2.8.14
redhat Ansible Engine>=2.9.0<2.9.12
Debian Debian Linux=10.0

Event History

Sep 11, 2020
CVE Published
via MITRE·05:59 PM
Data Sourced
via MITRE·05:59 PM
DescriptionSeverityWeakness
Feb 9, 2022
Advisory Published
via GitHub·09:59 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2020-14332?

CVE-2020-14332 is a vulnerability found in Ansible Engine when using module_args, allowing unauthorized users to read sensitive data.

2

How does CVE-2020-14332 impact confidentiality?

CVE-2020-14332 poses a threat to confidentiality, as unauthorized users can exploit this vulnerability to access sensitive data.

3

What is the severity level of CVE-2020-14332?

The severity level of CVE-2020-14332 is medium with a CVSS score of 5.5.

4

Which software versions are affected by CVE-2020-14332?

Ansible Engine versions up to 2.9.12 and 2.8.14, as well as Redhat Ansible Engine versions 2.8.0 to 2.8.14 and 2.9.0 to 2.9.12 are affected by CVE-2020-14332.

5

How can I fix CVE-2020-14332?

To fix CVE-2020-14332, update Ansible Engine to version 2.9.12 or Redhat Ansible Engine to version 2.8.14.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203