CVE-2020-1746
Ansible Tower vulnerability analysis and mitigation

Overview

A flaw was found in the Ansible Engine affecting versions 2.7.x before 2.7.17, 2.8.x before 2.8.11, and 2.9.x before 2.9.7, as well as Ansible Tower before and including versions 3.4.5, 3.5.5, and 3.6.3. The vulnerability exists in the ldap_attr and ldap_entry community modules, where the LDAP bind password is disclosed to stdout or a log file if a playbook task is written using the bind_pw in the parameters field (CVE Database, NVD).

Technical details

The vulnerability occurs when using the params module option in ldap_attr and ldap_entry modules. The issue specifically relates to the handling of the bind_pw parameter, which contains sensitive password information. When this parameter is included in the params field, it bypasses Ansible's normal parameter handling mechanisms, resulting in the password being exposed in logs or stdout (Red Hat Bugzilla).

Impact

The primary impact of this vulnerability is the potential exposure of LDAP bind passwords, which could lead to unauthorized access to LDAP services. The highest threat from this vulnerability is to data confidentiality, as sensitive authentication credentials could be exposed in log files or standard output (CVE Database).

Exploitability

The vulnerability can be exploited when a playbook task is written using the bind_pw parameter in the parameters field of the ldap_attr or ldap_entry modules. This requires access to either the system's log files or the ability to view the stdout output of the Ansible playbook execution (Red Hat Bugzilla).

Mitigation and workarounds

A workaround exists where playbooks can be rewritten to use the 'args' keyword instead of directly using bind_pw in parameters. The permanent fix is to upgrade to Ansible Engine versions 2.7.17, 2.8.11, or 2.9.7 or later, depending on your version track. For Ansible Tower users, upgrade to versions newer than 3.4.5, 3.5.5, or 3.6.3 (GitHub PR, Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related Ansible Tower vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-4112HIGH8.8
  • Ansible Tower logoAnsible Tower
  • cpe:2.3:a:redhat:ansible_tower
NoYesAug 25, 2022
CVE-2021-3583HIGH7.1
  • Ansible Tower logoAnsible Tower
  • python3-hwdata
NoYesSep 22, 2021
CVE-2020-14327MEDIUM5.5
  • Ansible Tower logoAnsible Tower
  • cpe:2.3:a:redhat:ansible_tower
NoYesMay 27, 2021
CVE-2020-14329LOW3.3
  • Ansible Tower logoAnsible Tower
  • cpe:2.3:a:redhat:ansible_tower
NoYesMay 27, 2021
CVE-2020-14328LOW3.3
  • Ansible Tower logoAnsible Tower
  • cpe:2.3:a:redhat:ansible_tower
NoYesMay 27, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management