Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-1753

16
FAUCET Score

CVE-2020-1753 is a medium-severity information disclosure vulnerability affecting Ansible Engine versions 2.7.x prior to 2.7.17, 2.8.x prior to 2.8.11, and 2.9.x prior to 2.9.7 when managing Kubernetes with the k8s module. This flaw causes sensitive parameters like passwords and tokens to be passed via the command line to kubectl, making them visible in process lists and log files, bypassing no_log directives. The vulnerability has a CVSS score of 5.5 (MEDIUM) with a local attack vector and low attack complexity, leading to high confidentiality impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.7.18CPE matchmatch criteria
cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:*
>= 2.8.0, < 2.8.11CPE matchmatch criteria
cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:*
>= 2.9.0, < 2.9.7CPE matchmatch criteria
cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:*
<= 3.3.4CPE matchmatch criteria
cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:*
>= 3.4.0, <= 3.4.5CPE matchmatch criteria
cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.0MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.3
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.51%
Probability of exploitation in next 30 days
EPSS Percentile
40.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0051 is in the 92nd percentile among its peer group of 15,940 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (17)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: ansibleFixed in: 2.8.12
pippatch availablevia ghsa
Product: ansibleFixed in: 2.9.7
pippatch availablevia ghsa
Product: ansibleFixed in: 2.7.18
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Engine 2.9 for RHEL 7Fixed in: ansible-0:2.9.7-1.el7ae
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Engine 2.9 for RHEL 8Fixed in: ansible-0:2.9.7-1.el8ae
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Engine 2 for RHEL 7Fixed in: ansible-0:2.9.7-1.el7ae
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Engine 2 for RHEL 8Fixed in: ansible-0:2.9.7-1.el8ae
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Tower 3.4 for RHEL 7Fixed in: ansible-tower-34/ansible-tower-memcached:1.4.15-28
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Tower 3.4 for RHEL 7Fixed in: ansible-tower-35/ansible-tower-memcached:1.4.15-28
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Tower 3.5 for RHEL 7Fixed in: ansible-tower-35/ansible-tower:3.5.6-1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Tower 3.4 for RHEL 7Fixed in: ansible-tower-37/ansible-tower-memcached-rhel7:1.4.15-28
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Engine 2.7 for RHEL 7Fixed in: ansible-0:2.7.18-1.el7ae
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Engine 2.8 for RHEL 7Fixed in: ansible-0:2.8.16-1.el7ae
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Engine 2.8 for RHEL 8Fixed in: ansible-0:2.8.16-1.el8ae
View patch
redhatvendor investigatingvia nvd_reference
View patch
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: ansible

Vendor Advisories (2)

pipGHSA-86hp-cj9j-33vvmedium

Insertion of Sensitive Information into Log File, Invocation of Process Using Visible Sensitive Information, and Exposure of Sensitive Information to an Unauthorized Actor in Ansible

Apr 7, 2021
redhatCVE-2020-1753Moderate

Ansible: kubectl connection plugin leaks sensitive information

Mar 9, 2020

References

bugzilla.redhat.com / show_bug.cgi
Issue TrackingVendor Advisory
github.com / ansible-collections/kubernetes/pull/51
ExploitPatchThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/DKPA4KC3OJSUFASUYMG66HKJE7ADNGFW
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/MRRYUU5ZBLPBXCYG6CFP35D64NP2UB2S
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/WQVOQD4VAIXXTVQAJKTN7NUGTJFE2PCB
security.gentoo.org / glsa/202006-11
Third Party Advisory
debian.org / security/2021/dsa-4950
Third Party Advisory