First published: Thu Feb 20 2020(Updated: )
A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when the ldap_attr and ldap_entry community modules are used. The issue discloses the LDAP bind password to stdout or a log file if a playbook task is written using the `bind_pw` in the parameters field. The highest threat from this vulnerability is data confidentiality.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
pip/ansible | >=2.9.0<2.9.7 | 2.9.7 |
pip/ansible | >=2.8.0<2.8.11 | 2.8.11 |
pip/ansible | <2.7.17 | 2.7.17 |
redhat/ansible-engine | <2.7.17 | 2.7.17 |
redhat/ansible-engine | <2.8.11 | 2.8.11 |
redhat/ansible-engine | <2.9.7 | 2.9.7 |
Redhat Ansible Engine | >=2.7.0<2.7.17 | |
Redhat Ansible Engine | >=2.8.0<2.8.11 | |
Redhat Ansible Engine | >=2.9.0<2.9.7 | |
Redhat Ansible Tower | >=3.4.0<=3.4.5 | |
Redhat Ansible Tower | >=3.5.0<=3.5.5 | |
Redhat Ansible Tower | >=3.6.0<=3.6.3 | |
Debian Debian Linux | =10.0 | |
debian/ansible | 2.7.7+dfsg-1+deb10u1 2.7.7+dfsg-1+deb10u2 2.10.7+merged+base+2.10.8+dfsg-1 7.3.0+dfsg-1 7.7.0+dfsg-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1746 is a vulnerability found in the Ansible Engine.
Ansible Engine versions 2.7.x before 2.7.17, 2.8.x before 2.8.11, and 2.9.x before 2.9.7 are affected.
Ansible Tower versions 3.4.5, 3.5.5, and 3.6.3 are affected.
CVE-2020-1746 has a medium severity.
To fix CVE-2020-1746, update Ansible Engine to versions 2.7.17, 2.8.11, or 2.9.7.