PT-2020-6568 · Red Hat+2 · Ansible Engine+3

Abadger

·

Published

2020-05-12

·

Updated

2025-11-21

·

CVE-2020-1746

CVSS v4.0

5.1

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ansible Engine versions 2.7.x through 2.7.16 Ansible Engine versions 2.8.x through 2.8.10 Ansible Engine versions 2.9.x through 2.9.6 Ansible Tower versions 3.4.5 and earlier Ansible Tower versions 3.5.5 and earlier Ansible Tower version 3.6.3
Description A flaw was found in the Ansible Engine affecting data confidentiality. The issue discloses the LDAP bind password to stdout or a log file if a playbook task is written using the bind pw in the parameters field when the ldap attr and ldap entry community modules are used. The highest threat from this vulnerability is data confidentiality.
Recommendations For Ansible Engine versions 2.7.x through 2.7.16, update to version 2.7.17 or later. For Ansible Engine versions 2.8.x through 2.8.10, update to version 2.8.11 or later. For Ansible Engine versions 2.9.x through 2.9.6, update to version 2.9.7 or later. For Ansible Tower versions 3.4.5 and earlier, update to a version later than 3.4.5. For Ansible Tower versions 3.5.5 and earlier, update to a version later than 3.5.5. For Ansible Tower version 3.6.3, update to a version later than 3.6.3. As a temporary workaround, consider avoiding the use of the bind pw parameter in playbook tasks until a patch is available. Restrict access to the ldap attr and ldap entry community modules to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2050
ALT-PU-2020-2069
BDU:2022-00238
CVE-2020-1746
DSA-4950-1
GHSA-J2H6-73X8-22C4
MGASA-2020-0217
OPENSUSE-SU-2022:0081-1
OPENSUSE-SU-2024:10615-1
OPENSUSE-SU-2024:14244-1
OPENSUSE-SU-2024:14536-1
OPENSUSE-SU-2025:15605-1
OPENSUSE-SU-2025:15753-1
PYSEC-2020-13
RHSA-2020:1541
RHSA-2020:1542
RHSA-2020:1543
RHSA-2020:1544
SUSE-SU-2020:3309-1

Affected Products

Alt Linux
Ansible Engine
Ansible Tower
Astra Linux