CVE-2020-14332

A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.
References
Link Resource
https://github.com/ansible/ansible/pull/71033 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14332 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:*

Information

Published : 2020-09-11 18:15

Updated : 2021-08-07 15:15


NVD link : CVE-2020-14332

Mitre link : CVE-2020-14332


JSON object : View

Products Affected

redhat

  • ansible_engine
CWE
CWE-532

Insertion of Sensitive Information into Log File