Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-10729

Опубликовано: 27 мая 2021
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.1
CVSS3: 5.5

Описание

A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as the template caching action for the same file since no re-evaluation happens. The highest threat from this vulnerability would be that all passwords are exposed at once for the file. This flaw affects Ansible Engine versions before 2.9.6.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

eoan

ignored

end of life
esm-apps/bionic

released

2.5.1+dfsg-1ubuntu0.1+esm5
esm-apps/focal

not-affected

2.9.6+dfsg-1
esm-apps/jammy

not-affected

esm-apps/noble

not-affected

esm-apps/xenial

released

2.0.0.2-2ubuntu1.3+esm5
esm-infra-legacy/trusty

not-affected

code not present
focal

not-affected

2.9.6+dfsg-1

Показывать по

EPSS

Процентиль: 27%
0.00099
Низкий

2.1 Low

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
redhat
около 8 лет назад

A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as the template caching action for the same file since no re-evaluation happens. The highest threat from this vulnerability would be that all passwords are exposed at once for the file. This flaw affects Ansible Engine versions before 2.9.6.

CVSS3: 5.5
nvd
больше 4 лет назад

A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as the template caching action for the same file since no re-evaluation happens. The highest threat from this vulnerability would be that all passwords are exposed at once for the file. This flaw affects Ansible Engine versions before 2.9.6.

CVSS3: 5.5
debian
больше 4 лет назад

A flaw was found in the use of insufficiently random values in Ansible ...

CVSS3: 5
github
больше 4 лет назад

Insufficiently random values in Ansible

CVSS3: 5.5
fstec
больше 4 лет назад

Уязвимость системы управления конфигурациями Ansible, связанная с использованием недостаточно случайных значений, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 27%
0.00099
Низкий

2.1 Low

CVSS2

5.5 Medium

CVSS3