Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-1738

Опубликовано: 16 мар. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.6
CVSS3: 3.9

Описание

A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

needs-triage

eoan

ignored

end of life
esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/xenial

needs-triage

esm-infra-legacy/trusty

needs-triage

focal

ignored

end of standard support, was needs-triage

Показывать по

EPSS

Процентиль: 34%
0.00139
Низкий

2.6 Low

CVSS2

3.9 Low

CVSS3

Связанные уязвимости

CVSS3: 3.9
redhat
почти 6 лет назад

A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

CVSS3: 3.9
nvd
почти 6 лет назад

A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

CVSS3: 3.9
debian
почти 6 лет назад

A flaw was found in Ansible Engine when the module package or service ...

CVSS3: 3.9
github
почти 4 года назад

Argument Injection in Ansible

suse-cvrf
почти 4 года назад

Security update for ansible

EPSS

Процентиль: 34%
0.00139
Низкий

2.6 Low

CVSS2

3.9 Low

CVSS3