Lucene search

K
redhatcveRedhat.comRH:CVE-2020-1746
HistoryFeb 28, 2020 - 7:46 p.m.

CVE-2020-1746

2020-02-2819:46:05
redhat.com
access.redhat.com
7

0.0005 Low

EPSS

Percentile

17.1%

A flaw was found in the Ansible Engine when the ldap_attr and ldap_entry community modules are used. The issue discloses the LDAP bind password to stdout or a log file if a playbook task is written using the bind_pw in the parameters field. The highest threat from this vulnerability is data confidentiality.

Mitigation

Using args keyword and embedding the ldap_auth variable instead of using bind_pw parameter would mitigate this issue.