Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-1739

Опубликовано: 12 мар. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 3.3
CVSS3: 3.9

Описание

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

2.9.7+dfsg-1
eoan

ignored

end of life
esm-apps/bionic

released

2.5.1+dfsg-1ubuntu0.1+esm5
esm-apps/focal

released

2.9.6+dfsg-1ubuntu0.1~esm3
esm-apps/jammy

not-affected

2.9.7+dfsg-1
esm-apps/noble

not-affected

2.9.7+dfsg-1
esm-apps/xenial

released

2.0.0.2-2ubuntu1.3+esm5
esm-infra-legacy/trusty

released

1.5.4+dfsg-1ubuntu0.1~esm3
focal

ignored

end of standard support, was needed

Показывать по

EPSS

Процентиль: 14%
0.00045
Низкий

3.3 Low

CVSS2

3.9 Low

CVSS3

Связанные уязвимости

CVSS3: 3.9
redhat
почти 6 лет назад

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

CVSS3: 3.9
nvd
почти 6 лет назад

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

CVSS3: 3.9
debian
почти 6 лет назад

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9 ...

CVSS3: 3.9
github
почти 5 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Ansible

CVSS3: 3.9
fstec
почти 6 лет назад

Уязвимость модуля svn системы управления конфигурациями Ansible, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность

EPSS

Процентиль: 14%
0.00045
Низкий

3.3 Low

CVSS2

3.9 Low

CVSS3