CVE-2020-1753: Infoleak
A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2.9.x versions prior to 2.9.7, when managing kubernetes using the k8s module. Sensitive parameters such as passwords and tokens are passed to kubectl from the command line, not using an environment variable or an input configuration file. This will disclose passwords and tokens from process list and nolog directive from debug module would not have any effect making these secrets being disclosed on stdout and log files.
Other sources
When the user configures 'kubectl' Ansible connection plugin to connect to Kubernetes and uses environment variables such as 'K8SAUTHPASSWORD' and 'K8SAUTHTOKEN' are revealed in stdout with verbose mode, logs and visible through process list.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ansibleto a version that resolves this vulnerability.Fixed in 2.7.7+dfsg-1+deb10u1Fixed in 2.7.7+dfsg-1+deb10u2Fixed in 2.10.7+merged+base+2.10.8+dfsg-1Fixed in 7.3.0+dfsg-1Fixed in 7.7.0+dfsg-3 - Upgrade
Upgrade
redhat/ansible-engineto a version that resolves this vulnerability.Fixed in 2.7.18 - Upgrade
Upgrade
redhat/ansible-engineto a version that resolves this vulnerability.Fixed in 2.8.11 - Upgrade
Upgrade
redhat/ansible-engineto a version that resolves this vulnerability.Fixed in 2.9.7 - Upgrade
Upgrade
pip/ansibleto a version that resolves this vulnerability.Fixed in 2.9.7 - Upgrade
Upgrade
pip/ansibleto a version that resolves this vulnerability.Fixed in 2.8.12 - Upgrade
Upgrade
pip/ansibleto a version that resolves this vulnerability.Fixed in 2.7.18 - Upgrade
Upgrade
Ansible Engineto a version that resolves this vulnerability.Fixed in 2.7.17 - Upgrade
Upgrade
Ansible Engineto a version that resolves this vulnerability.Fixed in 2.8.11 - Upgrade
Upgrade
Ansible Engineto a version that resolves this vulnerability.Fixed in 2.9.7
Event History
Frequently Asked Questions
What is CVE-2020-1753?
CVE-2020-1753 is a security flaw found in Ansible Engine when managing kubernetes using the k8s module.
Which versions of Ansible are affected by CVE-2020-1753?
All Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11, and all Ansible 2.9.x versions prior to 2.9.7 are affected by CVE-2020-1753.
What is the severity of CVE-2020-1753?
CVE-2020-1753 has a severity value of 4, which is considered medium.
How can I fix CVE-2020-1753?
To fix CVE-2020-1753, update Ansible to version 2.7.18, 2.8.11, or 2.9.7 depending on the version you are using.
Where can I find more information about CVE-2020-1753?
You can find more information about CVE-2020-1753 in the following references: [Link 1](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1811892), [Link 2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1811933), [Link 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1811934).