Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian: DLA-2202-1 Critical: Ansible Credentials Disclosure Issues

debian lts
Calendar Grey May 5, 2020
Dist Debian Esm H88
Ensure your ansible packages are updated on Debian 8, as recent versions have resolved security issues.
Several vulnerabilities were discovered in Ansible, a configuration management, deployment, and task execution system

Summary

CVE-2019-14846

Ansible was logging at the DEBUG level which lead to a disclosure
of credentials if a plugin used a library that logged credentials
at the DEBUG level. This flaw does not affect Ansible modules, as
those are executed in a separate process.


CVE-2020-1733

A race condition flaw was found when running a playbook with an
unprivileged become user. When Ansible needs to run a module with
become user, the temporary directory is created in /var/tmp. This
directory is created with "umask 77 && mkdir -p dir"; this
operation does not fail if the directory already exists and is
owned by another user. An attacker could take advantage to gain
control of the become user as the target directory can be
retrieved by iterating '/proc/pid/cmdline'.

CVE-2020-1739

A flaw was found when a password is set with the argument
"password" of svn module, it is used on svn command line,
disclosing to other users within the same node. An attacker could

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: ansible
Version: 1.7.2+dfsg-2+deb8u3
CVE ID: CVE-2019-14846 CVE-2020-1733 CVE-2020-1739 CVE-2020-1740
Debian Bug: 942188

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here