PT-2020-6569 · Red Hat+2 · Ansible Engine+2

Bcoca

·

Published

2020-03-16

·

Updated

2025-11-21

·

CVE-2020-1753

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ansible Engine versions 2.7.x prior to 2.7.17 Ansible Engine versions 2.8.x prior to 2.8.11 Ansible Engine versions 2.9.x prior to 2.9.7
Description A security flaw was found in Ansible Engine when managing Kubernetes using the k8s module. Sensitive parameters such as passwords and tokens are passed to kubectl from the command line, not using an environment variable or an input configuration file. This will disclose passwords and tokens from the process list, and the no log directive from the debug module would not have any effect, making these secrets disclosed on stdout and log files.
Recommendations For Ansible Engine versions 2.7.x prior to 2.7.17, update to version 2.7.17 or later. For Ansible Engine versions 2.8.x prior to 2.8.11, update to version 2.8.11 or later. For Ansible Engine versions 2.9.x prior to 2.9.7, update to version 2.9.7 or later. As a temporary workaround, consider restricting access to the k8s module until a patch is available. Avoid using sensitive parameters such as passwords and tokens in the k8s module until the issue is resolved.

Exploit

Fix

Insertion into Log File

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2050
ALT-PU-2020-2069
BDU:2022-00239
CVE-2020-1753
DSA-4950-1
GHSA-86HP-CJ9J-33VV
MGASA-2020-0217
OESA-2021-1349
OESA-2022-1950
OPENSUSE-SU-2022:0081-1
OPENSUSE-SU-2024:10615-1
OPENSUSE-SU-2024:14244-1
OPENSUSE-SU-2024:14536-1
OPENSUSE-SU-2025:15605-1
OPENSUSE-SU-2025:15753-1
PYSEC-2020-210
RHSA-2020:1541
RHSA-2020:1542
RHSA-2020:2142
SUSE-SU-2020:3309-1
SUSE-SU-2024:1509-1

Affected Products

Alt Linux
Ansible Engine
Astra Linux