Ansible: kubectl connection plugin leaks sensitive information
Published Mar 16, 2020
6.8
MEDIUMCVSS 4.0
EPSS 0.51%
Description
A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2.9.x versions prior to 2.9.7, when managing kubernetes using the k8s module. Sensitive parameters such as passwords and tokens are passed to kubectl from the command line, not using an environment variable or an input configuration file. This will disclose passwords and tokens from process list and no_log directive from debug module would not have any effect making these secrets being disclosed on stdout and log files.
Affected products
-
- Version all Ansible 2.7.x versions prior to 2.7.17StatusaffectedConstraints-
- Version all Ansible 2.8.x versions prior to 2.8.11StatusaffectedConstraints-
- Version all Ansible 2.9.x versions prior to 2.9.7StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Configuration 1
- < 2.7.18
- ≥ 2.8.0 · < 2.8.11
- ≥ 2.9.0 · < 2.9.7
- ≤ 3.3.4
- ≥ 3.4.0 · ≤ 3.4.5
- ≥ 3.5.0 · ≤ 3.5.5
- ≥ 3.6.0 · ≤ 3.6.3
Configuration 2
- 10.0
Configuration 3
- 30
- 31
- 32
No data.
Red Hat Ansible Engine 2 for RHEL 7
ansible-0:2.9.7-1.el7ae
Fixed · RHSA-2020:1542
Red Hat Ansible Engine 2 for RHEL 8
ansible-0:2.9.7-1.el8ae
Fixed · RHSA-2020:1542
Red Hat Ansible Engine 2.7 for RHEL 7
ansible-0:2.7.18-1.el7ae
Fixed · RHSA-2020:2142
Red Hat Ansible Engine 2.8 for RHEL 7
ansible-0:2.8.16-1.el7ae
Fixed · RHBA-2020:4195
Red Hat Ansible Engine 2.8 for RHEL 8
ansible-0:2.8.16-1.el8ae
Fixed · RHBA-2020:4195
Red Hat Ansible Engine 2.9 for RHEL 7
ansible-0:2.9.7-1.el7ae
Fixed · RHSA-2020:1541
Red Hat Ansible Engine 2.9 for RHEL 8
ansible-0:2.9.7-1.el8ae
Fixed · RHSA-2020:1541
Red Hat Ansible Tower 3.4 for RHEL 7
ansible-tower-34/ansible-tower-memcached:1.4.15-28
Fixed · RHBA-2020:0547
Red Hat Ansible Tower 3.4 for RHEL 7
ansible-tower-35/ansible-tower-memcached:1.4.15-28
Fixed · RHBA-2020:0547
Red Hat Ansible Tower 3.4 for RHEL 7
ansible-tower-37/ansible-tower-memcached-rhel7:1.4.15-28
Fixed · RHBA-2020:0547
Red Hat Ansible Tower 3.5 for RHEL 7
ansible-tower-35/ansible-tower:3.5.6-1
Fixed · RHBA-2020:1539
Red Hat Ceph Storage 2
ansible
Not affected
Red Hat Ceph Storage 3
ansible
Not affected
Red Hat OpenStack Platform 10 (Newton)
ansible
Out of support scope
Red Hat OpenStack Platform 13 (Queens)
ansible
Will not fix
Red Hat Storage 3
ansible
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Engine 2 for RHEL 7 | ansible-0:2.9.7-1.el7ae | Fixed | RHSA-2020:1542 |
| Red Hat Ansible Engine 2 for RHEL 8 | ansible-0:2.9.7-1.el8ae | Fixed | RHSA-2020:1542 |
| Red Hat Ansible Engine 2.7 for RHEL 7 | ansible-0:2.7.18-1.el7ae | Fixed | RHSA-2020:2142 |
| Red Hat Ansible Engine 2.8 for RHEL 7 | ansible-0:2.8.16-1.el7ae | Fixed | RHBA-2020:4195 |
| Red Hat Ansible Engine 2.8 for RHEL 8 | ansible-0:2.8.16-1.el8ae | Fixed | RHBA-2020:4195 |
| Red Hat Ansible Engine 2.9 for RHEL 7 | ansible-0:2.9.7-1.el7ae | Fixed | RHSA-2020:1541 |
| Red Hat Ansible Engine 2.9 for RHEL 8 | ansible-0:2.9.7-1.el8ae | Fixed | RHSA-2020:1541 |
| Red Hat Ansible Tower 3.4 for RHEL 7 | ansible-tower-34/ansible-tower-memcached:1.4.15-28 | Fixed | RHBA-2020:0547 |
| Red Hat Ansible Tower 3.4 for RHEL 7 | ansible-tower-35/ansible-tower-memcached:1.4.15-28 | Fixed | RHBA-2020:0547 |
| Red Hat Ansible Tower 3.4 for RHEL 7 | ansible-tower-37/ansible-tower-memcached-rhel7:1.4.15-28 | Fixed | RHBA-2020:0547 |
| Red Hat Ansible Tower 3.5 for RHEL 7 | ansible-tower-35/ansible-tower:3.5.6-1 | Fixed | RHBA-2020:1539 |
| Red Hat Ceph Storage 2 | ansible | Not affected | n/a |
| Red Hat Ceph Storage 3 | ansible | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | ansible | Out of support scope | n/a |
| Red Hat OpenStack Platform 13 (Queens) | ansible | Will not fix | n/a |
| Red Hat Storage 3 | ansible | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Ansible Engine 2.7.17, 2.8.10, and 2.9.6 as well as previous versions are affected. Ansible Tower 3.4.5, 3.5.5 and 3.6.3 as well as previous versions are affected. In Red Hat OpenStack Platform, because the flaw has a lower impact, ansible is not directly customer exposed, and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP ansible package.
Red Hat mitigation
Currently, there is no mitigation for this issue.
References (21)
- https://access.redhat.com/security/cve/CVE-2020-1753 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1811008 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1753 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0022 Advisory
- https://github.com/advisories/GHSA-86hp-cj9j-33vv Advisory
- https://github.com/ansible-collections/kubernetes/pull/51 x_refsource_CONFIRMExploitPatchThird Party Advisory
- https://github.com/ansible/ansible/commit/04ba05e003b268b83df6c106ba5c0f08548b1380
- https://github.com/ansible/ansible/commit/137caed836ef096945086cfe75dc11587b68db3a
- https://github.com/ansible/ansible/commit/273d8538dbe5a7b5c9954f1929d3bb00904c43f6
- https://github.com/ansible/ansible/pull/68195
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2020-210.yaml
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DKPA4KC3OJSUFASUYMG66HKJE7ADNGFW/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRRYUU5ZBLPBXCYG6CFP35D64NP2UB2S/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WQVOQD4VAIXXTVQAJKTN7NUGTJFE2PCB/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DKPA4KC3OJSUFASUYMG66HKJE7ADNGFW
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MRRYUU5ZBLPBXCYG6CFP35D64NP2UB2S
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WQVOQD4VAIXXTVQAJKTN7NUGTJFE2PCB
- https://nvd.nist.gov/vuln/detail/CVE-2020-1753
- https://security.gentoo.org/glsa/202006-11 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-1753
- https://www.debian.org/security/2021/dsa-4950 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.