SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-14332

Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data.

MEDIUM 5.5EPSS 0.41%

Does this matter?

Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.41% probability · 35th percentile
CISA KEV
Not listed
Weakness
CWE-117, CWE-532
Affected
redhat/ansible engine · debian/debian linux
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.