First published: Thu Feb 20 2020(Updated: )
A flaw was found in ldap_attr and ldap_entry community modules for Ansbile. This issue discloses the LDAP bind password to stdout or a log file if a playbook task is written using the bind_pw in the parameters field since nothing in the params field is evaluated for sensitive data.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/ansible | 2.7.7+dfsg-1+deb10u1 2.7.7+dfsg-1+deb10u2 2.10.7+merged+base+2.10.8+dfsg-1 7.3.0+dfsg-1 7.7.0+dfsg-3 | |
redhat/ansible-engine | <2.7.17 | 2.7.17 |
redhat/ansible-engine | <2.8.11 | 2.8.11 |
redhat/ansible-engine | <2.9.7 | 2.9.7 |
pip/ansible | >=2.7.0a1<2.7.17 | 2.7.17 |
pip/ansible | >=2.9.0a1<2.9.7 | 2.9.7 |
pip/ansible | >=2.8.0a1<2.8.11 | 2.8.11 |
Red Hat Ansible Engine | >=2.7.0<2.7.17 | |
Red Hat Ansible Engine | >=2.8.0<2.8.11 | |
Red Hat Ansible Engine | >=2.9.0<2.9.7 | |
Red Hat Ansible Tower | >=3.4.0<=3.4.5 | |
Red Hat Ansible Tower | >=3.5.0<=3.5.5 | |
Red Hat Ansible Tower | >=3.6.0<=3.6.3 | |
Debian | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1746 is a vulnerability found in the Ansible Engine.
Ansible Engine versions 2.7.x before 2.7.17, 2.8.x before 2.8.11, and 2.9.x before 2.9.7 are affected.
Ansible Tower versions 3.4.5, 3.5.5, and 3.6.3 are affected.
CVE-2020-1746 has a medium severity.
To fix CVE-2020-1746, update Ansible Engine to versions 2.7.17, 2.8.11, or 2.9.7.