CVE-2020-1746

Description

A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when the ldap_attr and ldap_entry community modules are used. The issue discloses the LDAP bind password to stdout or a log file if a playbook task is written using the bind_pw in the parameters field. The highest threat from this vulnerability is data confidentiality.

Risk Information

Base Score
5.0
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.061

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Python-ansible 2.7.17Windows
Multiple vulnerabilities are fixed in Python-ansible 2.8.11Windows
Multiple vulnerabilities are fixed in Python-ansible 2.9.7Windows
Multiple vulnerabilities are affected in Python-ansible 2.8.10Windows
Multiple vulnerabilities are affected in Python-ansible 2.9.6Windows
ansible security update(DSA-4950-1) ansible_2.7.7+dfsg-1+deb10u1_all.debLinux
ansible security update(DSA-4950-1) Debian_ansible_2.7.7+dfsg-1+deb10u1_all.debLinux
Multiple vulnerabilities are fixed in Python-ansible for linux 2.7.17Linux
Multiple vulnerabilities are fixed in Python-ansible for linux 2.8.11Linux
Multiple vulnerabilities are fixed in Python-ansible for linux 2.9.7Linux
Multiple vulnerabilities are affected in Python-ansible for linux 2.8.10Linux
Multiple vulnerabilities are affected in Python-ansible for linux 2.9.6Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234