Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-1738

Опубликовано: 16 мар. 2020
Источник: nvd
CVSS3: 3.9
CVSS2: 2.6
EPSS Низкий

Описание

A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
Версия до 2.7.16 (включая)
cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
Версия от 2.8.0 (включая) до 2.8.8 (включая)
cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
Версия от 2.9.0 (включая) до 2.9.5 (включая)
cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:*
Версия до 3.3.4 (включая)
cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:*
Версия от 3.3.5 (включая) до 3.4.5 (включая)
cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:*
Версия от 3.5.0 (включая) до 3.5.5 (включая)
cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:*
Версия от 3.6.0 (включая) до 3.6.3 (включая)
cpe:2.3:a:redhat:cloudforms_management_engine:5.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*

EPSS

Процентиль: 34%
0.00139
Низкий

3.9 Low

CVSS3

2.6 Low

CVSS2

Дефекты

CWE-88
CWE-88

Связанные уязвимости

CVSS3: 3.9
ubuntu
почти 6 лет назад

A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

CVSS3: 3.9
redhat
почти 6 лет назад

A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

CVSS3: 3.9
debian
почти 6 лет назад

A flaw was found in Ansible Engine when the module package or service ...

CVSS3: 3.9
github
почти 4 года назад

Argument Injection in Ansible

suse-cvrf
почти 4 года назад

Security update for ansible

EPSS

Процентиль: 34%
0.00139
Низкий

3.9 Low

CVSS3

2.6 Low

CVSS2

Дефекты

CWE-88
CWE-88