An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed tasks to read keys used in playbooks from other users within the uri module. The highest threat from this vulnerability is to data confidentiality.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-4950-1 ansible security update
EUVD EUVD EUVD-2020-0025 An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed tasks to read keys used in playbooks from other users within the uri module. The highest threat from this vulnerability is to data confidentiality.
Github GHSA Github GHSA GHSA-785x-qw4v-6872 Improper Output Neutralization and Improper Encoding or Escaping of Output for Logs in ansible
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-04T12:39:36.412Z

Reserved: 2020-06-17T00:00:00

Link: CVE-2020-14330

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-09-11T18:15:13.147

Modified: 2024-11-21T05:03:01.510

Link: CVE-2020-14330

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-03-23T00:00:00Z

Links: CVE-2020-14330 - Bugzilla

cve-icon OpenCVE Enrichment

No data.