CVE-2020-14330

Name
CVE-2020-14330
Description
An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed tasks to read keys used in playbooks from other users within the uri module. The highest threat from this vulnerability is to data confidentiality.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Third Party Advisory https://github.com/ansible/ansible/issues/68400
Issue Tracking https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14330
Third Party Advisory https://www.debian.org/security/2021/dsa-4950

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:* ansible_engine >= None < 2.10.0
cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:* ansible_engine >= None < 2.9.12

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
ansible-base edge-main 2.9.13-r0 None fixed
ansible-base edge-community 2.9.13-r0 None fixed
ansible 3.12-main 2.9.13-r0 None fixed
ansible 3.11-main 2.9.13-r0 None fixed
ansible 3.10-main 2.8.15-r0 None fixed