Sensitive Information Exposure in Ansible by Red Hat
CVE-2020-10782

6.5MEDIUM

Key Information:

Vendor
Red Hat
Vendor
CVE Published:
18 June 2020

Summary

A vulnerability in Ansible version 3.7.0 allows for the exposure of sensitive information, such as tokens and secrets, due to improperly set world-readable permissions in the rsyslog configuration file. This flaw poses a risk to confidentiality as unintended access to sensitive data may occur. Users are encouraged to update to Ansible version 3.7.1, where this issue has been addressed.

Affected Version(s)

Ansible Tower Affected: version 3.7.0

Ansible Tower Fixed: version 3.7.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.