Improper Output Neutralization Vulnerability in Ansible's URI Module
CVE-2020-14330

5MEDIUM

Key Information:

Vendor

Red Hat

Status
Vendor
CVE Published:
11 September 2020

What is CVE-2020-14330?

Ansible contains an improper output neutralization vulnerability within its URI module. This flaw enables attackers to access sensitive logs or outputs generated during task execution, revealing keys used in playbooks from other users. Consequently, this can compromise the confidentiality of data, allowing unauthorized users to gain insights into confidential information stored in the logs.

Affected Version(s)

Ansible 2.10.0

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.