
Cloud Vulnerability DB
A community-led vulnerabilities database
A flaw was found in the Ansible Engine affecting versions 2.7.x before 2.7.17, 2.8.x before 2.8.11, and 2.9.x before 2.9.7, as well as Ansible Tower before and including versions 3.4.5, 3.5.5, and 3.6.3. The vulnerability exists in the ldap_attr and ldap_entry community modules, where the LDAP bind password is disclosed to stdout or a log file if a playbook task is written using the bind_pw in the parameters field (CVE Database, NVD).
The vulnerability occurs when using the params module option in ldap_attr and ldap_entry modules. The issue specifically relates to the handling of the bind_pw parameter, which contains sensitive password information. When this parameter is included in the params field, it bypasses Ansible's normal parameter handling mechanisms, resulting in the password being exposed in logs or stdout (Red Hat Bugzilla).
The primary impact of this vulnerability is the potential exposure of LDAP bind passwords, which could lead to unauthorized access to LDAP services. The highest threat from this vulnerability is to data confidentiality, as sensitive authentication credentials could be exposed in log files or standard output (CVE Database).
The vulnerability can be exploited when a playbook task is written using the bind_pw parameter in the parameters field of the ldap_attr or ldap_entry modules. This requires access to either the system's log files or the ability to view the stdout output of the Ansible playbook execution (Red Hat Bugzilla).
A workaround exists where playbooks can be rewritten to use the 'args' keyword instead of directly using bind_pw in parameters. The permanent fix is to upgrade to Ansible Engine versions 2.7.17, 2.8.11, or 2.9.7 or later, depending on your version track. For Ansible Tower users, upgrade to versions newer than 3.4.5, 3.5.5, or 3.6.3 (GitHub PR, Red Hat Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."