
Cloud Vulnerability DB
A community-led vulnerabilities database
A security vulnerability (CVE-2020-14332) was discovered in the Ansible Engine when using module_args. The flaw specifically affects tasks executed with check mode (--check-mode), where sensitive data exposed in the event data is not properly neutralized. This vulnerability was discovered and disclosed in June 2020 (CVE Mitre, NVD).
The vulnerability occurs specifically in the copy module's handling of the content parameter during check mode operations. When running with sufficient verbosity (-vvv) on the CLI or in AWX/Tower environments, the module fails to properly censor sensitive information in the module_args. In AWX/Tower, this exposure occurs regardless of verbosity settings as the data is saved in event data (Red Hat Bugzilla).
The primary impact of this vulnerability is on confidentiality, as it allows unauthorized users to read sensitive data that should have been censored. This exposure is particularly concerning in AWX/Tower environments where the sensitive information is stored in event data regardless of verbosity settings (CVE Mitre).
The vulnerability can be exploited when using the Ansible Engine with check mode (--check-mode) and either high verbosity settings in CLI or in any verbosity setting within AWX/Tower environments (Red Hat Bugzilla).
The vulnerability was fixed in multiple Ansible versions including ansible-engine 2.9.12 and ansible-engine 2.8.14. The fix involves properly redacting the 'content' parameter from module_args invocation in check mode. Users are advised to upgrade to these or later versions (GitHub PR, Debian Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."