Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-1738

Опубликовано: 16 мар. 2020
Источник: debian
EPSS Низкий

Описание

A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ansibleunfixedpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1802164

  • https://github.com/ansible/ansible/issues/67796

  • Marked unimportant as for exploitation it requires already a remote that is

  • compromised, cf. https://github.com/ansible/ansible/issues/67796#issuecomment-614656017

EPSS

Процентиль: 32%
0.00384
Низкий

Связанные уязвимости

CVSS3: 3.9
ubuntu
больше 6 лет назад

A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

CVSS3: 3.9
redhat
больше 6 лет назад

A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

CVSS3: 3.9
nvd
больше 6 лет назад

A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

CVSS3: 3.9
github
больше 4 лет назад

Argument Injection in Ansible

suse-cvrf
больше 4 лет назад

Security update for ansible

EPSS

Процентиль: 32%
0.00384
Низкий