Логотип exploitDog
bind:CVE-2020-10684
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-10684

Количество 7

Количество 7

ubuntu логотип

CVE-2020-10684

почти 6 лет назад

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.

CVSS3: 7.9
EPSS: Низкий
redhat логотип

CVE-2020-10684

почти 6 лет назад

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.

CVSS3: 7.9
EPSS: Низкий
nvd логотип

CVE-2020-10684

почти 6 лет назад

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.

CVSS3: 7.9
EPSS: Низкий
debian логотип

CVE-2020-10684

почти 6 лет назад

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9. ...

CVSS3: 7.9
EPSS: Низкий
github логотип

GHSA-p62g-jhg6-v3rq

почти 5 лет назад

Code Injection, Race Condition, and Execution with Unnecessary Privileges in Ansible

CVSS3: 7.1
EPSS: Низкий
fstec логотип

BDU:2020-05829

почти 6 лет назад

Уязвимость системы управления конфигурациями Ansible, связанная с ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

CVSS2: 3.6
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:0081-1

почти 4 года назад

Security update for ansible

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-10684

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.

CVSS3: 7.9
0%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-10684

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.

CVSS3: 7.9
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2020-10684

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.

CVSS3: 7.9
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2020-10684

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9. ...

CVSS3: 7.9
0%
Низкий
почти 6 лет назад
github логотип
GHSA-p62g-jhg6-v3rq

Code Injection, Race Condition, and Execution with Unnecessary Privileges in Ansible

CVSS3: 7.1
0%
Низкий
почти 5 лет назад
fstec логотип
BDU:2020-05829

Уязвимость системы управления конфигурациями Ansible, связанная с ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

CVSS2: 3.6
0%
Низкий
почти 6 лет назад
suse-cvrf логотип
openSUSE-SU-2022:0081-1

Security update for ansible

почти 4 года назад

Уязвимостей на страницу