Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-1739

Опубликовано: 18 фев. 2020
Источник: redhat
CVSS3: 3.9
EPSS Низкий

Описание

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

A flaw was found in Ansible Engine. When a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

Отчет

Ansible Engine 2.7.16, 2.8.10, and 2.9.6 as well as previous versions are affected. Ansible Tower 3.4.5, 3.5.5 and 3.6.3 as well as previous versions are affected. In Red Hat OpenStack Platform, because the flaw has a lower impact, ansible is not directly customer exposed, and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP ansible package.

Меры по смягчению последствий

Instead of using the parameter 'password' of the subversion module, provide the password with stdin.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5ansible-towerNot affected
Red Hat Ceph Storage 2ansibleOut of support scope
Red Hat Ceph Storage 3ansibleAffected
Red Hat OpenStack Platform 10 (Newton)ansibleOut of support scope
Red Hat OpenStack Platform 13 (Queens)ansibleWill not fix
Red Hat Storage 3ansibleWill not fix
Red Hat Ansible Engine 2.7 for RHEL 7ansibleFixedRHSA-2020:154422.04.2020
Red Hat Ansible Engine 2.8 for RHEL 7ansibleFixedRHSA-2020:154322.04.2020
Red Hat Ansible Engine 2.8 for RHEL 8ansibleFixedRHSA-2020:154322.04.2020
Red Hat Ansible Engine 2.9 for RHEL 7ansibleFixedRHSA-2020:154122.04.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1802178ansible: svn module leaks password when specified as a parameter

EPSS

Процентиль: 14%
0.00045
Низкий

3.9 Low

CVSS3

Связанные уязвимости

CVSS3: 3.9
ubuntu
почти 6 лет назад

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

CVSS3: 3.9
nvd
почти 6 лет назад

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

CVSS3: 3.9
debian
почти 6 лет назад

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9 ...

CVSS3: 3.9
github
почти 5 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Ansible

CVSS3: 3.9
fstec
почти 6 лет назад

Уязвимость модуля svn системы управления конфигурациями Ansible, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность

EPSS

Процентиль: 14%
0.00045
Низкий

3.9 Low

CVSS3

Уязвимость CVE-2020-1739