Improper Output Neutralization Vulnerability in Ansible's URI Module
CVE-2020-14330
5MEDIUM
Summary
Ansible contains an improper output neutralization vulnerability within its URI module. This flaw enables attackers to access sensitive logs or outputs generated during task execution, revealing keys used in playbooks from other users. Consequently, this can compromise the confidentiality of data, allowing unauthorized users to gain insights into confidential information stored in the logs.
Affected Version(s)
Ansible 2.10.0
References
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved