CVE-2020-25635

Description

A flaw was found in Ansible Base. When using the aws_ssm connection plugin as a garbage collector, it is not working after the playbook run is completed due to the file remaining in the bucket, which exposes the data. The highest threat from this vulnerability is to confidentiality.

Statement

Ansible collection aws_ssm connection community plugin 1.2.1 and previous versions until 1.0.0 when it was introduced to this plugin, are the versions affected by this flaw.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Understanding the Weakness (CWE)

Confidentiality

Technical Impact: Read Files or Directories; Read Application Data

Sensitive data may be exposed to an unauthorized actor in another control sphere. This may have a wide range of secondary consequences that will depend on what data is exposed. One possibility is the exposure of system data - such as file locations, software versions, or device data - that allow an attacker to craft a specific, more effective attack. Alternately, insufficient redaction of Private Personal Information (PPI), Personally Identifiable Information (PII), or other types of information might not harm the secure operation of the product itself, but could be violations of expectations by the product's users.

Acknowledgements

Red Hat would like to thank Abel Luck (The Guardian Project) for reporting this issue.

Frequently Asked Questions

Want to get errata notifications? Sign up here.