CVE-2020-14330
Summary
| CVE | CVE-2020-14330 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-11 18:15:00 UTC |
| Updated | 2023-11-07 03:17:00 UTC |
| Description | An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed tasks to read keys used in playbooks from other users within the uri module. The highest threat from this vulnerability is to data confidentiality. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1856815 – (CVE-2020-14330) CVE-2020-14330 Ansible: masked keys for uri module are exposed into content and json output |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Vendor Advisory |
| Debian -- Security Information -- DSA-4950-1 ansible |
DEBIAN |
www.debian.org |
|
| uri module set string with masked content into content and json output · Issue #68400 · ansible/ansible · GitHub |
MISC |
github.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178744 Debian Security Update for ansible (DSA 4950-1)
- 356251 Amazon Linux Security Advisory for ansible : ALASANSIBLE2-2023-006
- 500006 Alpine Linux Security Update for ansible
- 501347 Alpine Linux Security Update for ansible-base