PT-2020-6576 · Ansible+2 · Ansible+2

Hungluong5791

·

Published

2020-09-11

·

Updated

2026-06-03

·

CVE-2020-14330

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ansible (affected versions not specified)
Description The issue is related to an improper output neutralization for logs flaw in the uri module of Ansible, where sensitive data is exposed to content and json output. This allows an attacker to access the logs or outputs of performed tasks to read keys used in playbooks from other users within the uri module. The highest threat from this issue is to data confidentiality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Insertion into Log File

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2923
ALT-PU-2020-3006
ALT-PU-2021-1800
BDU:2022-00279
CVE-2020-14330
DSA-4950-1
GHSA-785X-QW4V-6872
OPENSUSE-SU-2022:0081-1
OPENSUSE-SU-2024:10615-1
OPENSUSE-SU-2024:14244-1
OPENSUSE-SU-2024:14536-1
OPENSUSE-SU-2025:15605-1
OPENSUSE-SU-2025:15753-1
OPENSUSE-SU-2026:10944-1
PYSEC-2020-3
RHSA-2020:3600
SUSE-SU-2020:3309-1
SUSE-SU-2024:1509-1

Affected Products

Alt Linux
Ansible
Astra Linux