CVE-2020-1746: Infoleak
A flaw was found in ldapattr and ldapentry community modules for Ansbile. This issue discloses the LDAP bind password to stdout or a log file if a playbook task is written using the bindpw in the parameters field since nothing in the params field is evaluated for sensitive data.
Other sources
A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when the ldapattr and ldapentry community modules are used. The issue discloses the LDAP bind password to stdout or a log file if a playbook task is written using the bindpw in the parameters field. The highest threat from this vulnerability is data confidentiality.
— GitHub
A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when the ldapattr and ldapentry community modules are used. The issue discloses the LDAP bind password to stdout or a log file if a playbook task is written using the bindpw in the parameters field. The highest threat from this vulnerability is data confidentiality.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-1746?
CVE-2020-1746 is a vulnerability found in the Ansible Engine.
Which versions of Ansible Engine are affected by CVE-2020-1746?
Ansible Engine versions 2.7.x before 2.7.17, 2.8.x before 2.8.11, and 2.9.x before 2.9.7 are affected.
Which Ansible Tower versions are affected by CVE-2020-1746?
Ansible Tower versions 3.4.5, 3.5.5, and 3.6.3 are affected.
What is the severity of CVE-2020-1746?
CVE-2020-1746 has a medium severity.
How can I fix CVE-2020-1746?
To fix CVE-2020-1746, update Ansible Engine to versions 2.7.17, 2.8.11, or 2.9.7.