Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-1736

Опубликовано: 16 мар. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.1
CVSS3: 2.2

Описание

A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be changed to have less restrictive permissions before the move. This could lead to the disclosure of sensitive data. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

needs-triage

eoan

ignored

end of life
esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

esm-apps/xenial

ignored

end of ESM support, was needs-triage

Показывать по

EPSS

Процентиль: 34%
0.00405
Низкий

2.1 Low

CVSS2

2.2 Low

CVSS3

Связанные уязвимости

CVSS3: 2.2
redhat
больше 6 лет назад

A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be changed to have less restrictive permissions before the move. This could lead to the disclosure of sensitive data. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

CVSS3: 2.2
nvd
больше 6 лет назад

A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be changed to have less restrictive permissions before the move. This could lead to the disclosure of sensitive data. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

CVSS3: 2.2
debian
больше 6 лет назад

A flaw was found in Ansible Engine when a file is moved using atomic_m ...

CVSS3: 3.3
github
больше 4 лет назад

Incorrect Permission Assignment for Critical Resource in Ansible

suse-cvrf
больше 4 лет назад

Security update for ansible

EPSS

Процентиль: 34%
0.00405
Низкий

2.1 Low

CVSS2

2.2 Low

CVSS3