Improper Output Neutralization Vulnerability in Ansible's URI Module
CVE-2020-14330

5MEDIUM

Key Information:

Vendor
Red Hat
Status
Vendor
CVE Published:
11 September 2020

Summary

Ansible contains an improper output neutralization vulnerability within its URI module. This flaw enables attackers to access sensitive logs or outputs generated during task execution, revealing keys used in playbooks from other users. Consequently, this can compromise the confidentiality of data, allowing unauthorized users to gain insights into confidential information stored in the logs.

Affected Version(s)

Ansible 2.10.0

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.