Логотип exploitDog
bind:CVE-2020-14365
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-14365

Количество 7

Количество 7

ubuntu логотип

CVE-2020-14365

больше 5 лет назад

A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2020-14365

больше 5 лет назад

A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2020-14365

больше 5 лет назад

A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2020-14365

больше 5 лет назад

A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before ...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-m429-fhmv-c6q2

почти 5 лет назад

Improper Verification of Cryptographic Signature in ansible

CVSS3: 7.1
EPSS: Низкий
fstec логотип

BDU:2022-00281

больше 5 лет назад

Уязвимость модуля dnf системы управления конфигурациями Ansible, связанная с некорректным подтверждением криптографической подписи данных, позволяющая нарушителю нарушить целостность данных, а также вызвать отказ в обслуживании

CVSS3: 7.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1509-1

почти 2 года назад

Security update for SUSE Manager Client Tools

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-14365

A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.

CVSS3: 7.1
0%
Низкий
больше 5 лет назад
redhat логотип
CVE-2020-14365

A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.

CVSS3: 6.3
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-14365

A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.

CVSS3: 7.1
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-14365

A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before ...

CVSS3: 7.1
0%
Низкий
больше 5 лет назад
github логотип
GHSA-m429-fhmv-c6q2

Improper Verification of Cryptographic Signature in ansible

CVSS3: 7.1
0%
Низкий
почти 5 лет назад
fstec логотип
BDU:2022-00281

Уязвимость модуля dnf системы управления конфигурациями Ansible, связанная с некорректным подтверждением криптографической подписи данных, позволяющая нарушителю нарушить целостность данных, а также вызвать отказ в обслуживании

CVSS3: 7.1
0%
Низкий
больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2024:1509-1

Security update for SUSE Manager Client Tools

почти 2 года назад

Уязвимостей на страницу