CVE-2020-1753
MediumAdvisory
Published 16 Mar 2020In the index since 8 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.005
- 42nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 5
- of 17,781 indexed, latest versions
- Container images
- 6
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
Insertion of Sensitive Information into Log File, Invocation of Process Using Visible Sensitive Information, and Exposure of Sensitive Information to an Unauthorized Actor in Ansible
Carried by container images the latest versions of 5 of 17,781 indexed charts deploy, on 6 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| ansiblepypi | 2.5.0, 2.5.2, 2.5.3, 2.9.6 | 2.7.18, 2.9.7 | 6 |
| ansibledeb | 2.5.3-1ppa~trusty | no fix listed | 2 |
Charts affected
5 by stars
Container images carrying it
6 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| omecproject/ | cfdb566dd949 | ansible | 2.7.18 | 2 |
| galaxy/ | 0267bad550e6 | ansible ansible | no fix listed 2.7.18 | 1 |
| galaxy/ | 8e577a626dfd | ansible ansible | no fix listed 2.7.18 | 1 |
| omecproject/ | d109a8e57e71 | ansible | 2.7.18 | 1 |
| openwhisk/ | c80dba0de3aa | ansible | 2.7.18 | 1 |
| pnnlmiscscripts/ | 155131891741 | ansible | 2.9.7 | 1 |