CVE-2020-10782
Summary
| CVE | CVE-2020-10782 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-18 13:15:00 UTC |
| Updated | 2023-11-07 03:14:00 UTC |
| Description | An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable and exposed from the rsyslog configuration file, which has set the wrong world-readable permissions. The highest threat from this vulnerability is to confidentiality. This is fixed in Ansible version 3.7.1. |
Risk And Classification
Problem Types: CWE-732
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Ansible Tower | 3.7.0 | All | All | All |
| Application | Redhat | Ansible Tower | 3.7.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1847843 – (CVE-2020-10782) CVE-2020-10782 Tower: rsyslog configuration has world readable permissions | CONFIRM | bugzilla.redhat.com | Issue Tracking |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.