PT-2020-5969 · Red Hat+1 · Ansible+2

Borja Tarraso

·

Published

2020-06-18

·

Updated

2021-10-26

·

CVE-2020-10782

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ansible version 3.7.0 Ansible Tower versions prior to 3.7.1
Description A flaw in the rsyslog configuration file was found, causing sensitive information such as tokens and secrets to be exposed due to incorrect world-readable permissions. This issue poses a significant threat to confidentiality.
Recommendations For Ansible version 3.7.0, update to version 3.7.1 to resolve the issue. For Ansible Tower versions prior to 3.7.1, update to version 3.7.1 or later to fix the problem.

Fix

Incorrect Permission

Information Disclosure

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02145
CVE-2020-10782

Affected Products

Ansible
Ansible Tower
Rsyslog