2.1
CVSSv2

CVE-2020-1753

Published: 16/03/2020 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 188
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A security flaw was found in Ansible Engine, all Ansible 2.7.x versions before 2.7.17, all Ansible 2.8.x versions before 2.8.11 and all Ansible 2.9.x versions before 2.9.7, when managing kubernetes using the k8s module. Sensitive parameters such as passwords and tokens are passed to kubectl from the command line, not using an environment variable or an input configuration file. This will disclose passwords and tokens from process list and no_log directive from debug module would not have any effect making these secrets being disclosed on stdout and log files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat ansible tower

redhat ansible engine

debian debian linux 10.0

fedoraproject fedora 30

fedoraproject fedora 31

fedoraproject fedora 32

Vendor Advisories

Several vulnerabilities have been found in Ansible, a configuration management, deployment and task execution system, which could result in information disclosure or argument injection In addition a race condition in become_user was fixed For the stable distribution (buster), these problems have been fixed in version 277+dfsg-1+deb10u1 We reco ...
Synopsis Important: Ansible security and bug fix update (297) Type/Severity Security Advisory: Important Topic An update for ansible is now available for Ansible Engine 29Red Hat Product Security has rated this update as having a security impactof Important A Common Vulnerability Scoring System (CVSS) b ...
Synopsis Important: Ansible security and bug fix update (297) Type/Severity Security Advisory: Important Topic An update for ansible is now available for Ansible Engine 2Red Hat Product Security has rated this update as having a security impactof Important A Common Vulnerability Scoring System (CVSS) bas ...
Synopsis Moderate: Ansible security and bug fix update (2718) Type/Severity Security Advisory: Moderate Topic An update for ansible is now available for Ansible Engine 27Red Hat Product Security has rated this update as having a security impactof Moderate A Common Vulnerability Scoring System (CVSS) bas ...
A flaw was found in Ansible Engine, all versions 27x, 28x and 29x prior to 2717, 289 and 296 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean An attacker could take advantage of this by altering the ansible_facts, such as an ...