Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-1739

Опубликовано: 12 мар. 2020
Источник: debian
EPSS Низкий

Описание

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ansiblefixed2.9.7+dfsg-1package
ansibleend-of-lifestretchpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1802178

  • https://github.com/ansible/ansible/issues/67797

  • https://github.com/ansible/ansible/pull/67829

  • https://github.com/ansible/ansible/commit/d91658ec0c8434c82c3ef98bfe9eb4e1027a43a3

EPSS

Процентиль: 14%
0.00045
Низкий

Связанные уязвимости

CVSS3: 3.9
ubuntu
почти 6 лет назад

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

CVSS3: 3.9
redhat
почти 6 лет назад

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

CVSS3: 3.9
nvd
почти 6 лет назад

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

CVSS3: 3.9
github
почти 5 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Ansible

CVSS3: 3.9
fstec
почти 6 лет назад

Уязвимость модуля svn системы управления конфигурациями Ansible, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность

EPSS

Процентиль: 14%
0.00045
Низкий