SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-1746

The issue discloses the LDAP bind password to stdout or a log file if a playbook task is written using the bind_pw in the parameters field.

MEDIUM 5.0EPSS 0.41%

Does this matter?

Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when the ldap_attr and ldap_entry community modules are used. The issue discloses the LDAP bind password to stdout or a log file if a playbook task is written using the bind_pw in the parameters field. The highest threat from this vulnerability is data confidentiality.

CVSS 3.1
5.0 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
EPSS
0.41% probability · 34th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
redhat/ansible engine · redhat/ansible tower · debian/debian linux
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.