PT-2020-5969 · Red Hat+1 · Ansible+2
Borja Tarraso
·
Published
2020-06-18
·
Updated
2021-10-26
·
CVE-2020-10782
CVSS v3.1
6.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ansible version 3.7.0
Ansible Tower versions prior to 3.7.1
Description
A flaw in the rsyslog configuration file was found, causing sensitive information such as tokens and secrets to be exposed due to incorrect world-readable permissions. This issue poses a significant threat to confidentiality.
Recommendations
For Ansible version 3.7.0, update to version 3.7.1 to resolve the issue.
For Ansible Tower versions prior to 3.7.1, update to version 3.7.1 or later to fix the problem.
Fix
Incorrect Permission
Information Disclosure
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ansible
Ansible Tower
Rsyslog