First published: Thu Feb 20 2020(Updated: )
A flaw was found in ldap_attr and ldap_entry community modules for Ansbile. This issue discloses the LDAP bind password to stdout or a log file if a playbook task is written using the bind_pw in the parameters field since nothing in the params field is evaluated for sensitive data.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Ansible Engine | >=2.7.0<2.7.17 | |
Redhat Ansible Engine | >=2.8.0<2.8.11 | |
Redhat Ansible Engine | >=2.9.0<2.9.7 | |
Redhat Ansible Tower | >=3.4.0<=3.4.5 | |
Redhat Ansible Tower | >=3.5.0<=3.5.5 | |
Redhat Ansible Tower | >=3.6.0<=3.6.3 | |
Debian Debian Linux | =10.0 | |
debian/ansible | 2.7.7+dfsg-1+deb10u1 2.7.7+dfsg-1+deb10u2 2.10.7+merged+base+2.10.8+dfsg-1 7.3.0+dfsg-1 7.7.0+dfsg-3 | |
redhat/ansible-engine | <2.7.17 | 2.7.17 |
redhat/ansible-engine | <2.8.11 | 2.8.11 |
redhat/ansible-engine | <2.9.7 | 2.9.7 |
pip/ansible | >=2.7.0a1<2.7.17 | 2.7.17 |
pip/ansible | >=2.9.0a1<2.9.7 | 2.9.7 |
pip/ansible | >=2.8.0a1<2.8.11 | 2.8.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1746 is a vulnerability found in the Ansible Engine.
Ansible Engine versions 2.7.x before 2.7.17, 2.8.x before 2.8.11, and 2.9.x before 2.9.7 are affected.
Ansible Tower versions 3.4.5, 3.5.5, and 3.6.3 are affected.
CVE-2020-1746 has a medium severity.
To fix CVE-2020-1746, update Ansible Engine to versions 2.7.17, 2.8.11, or 2.9.7.