CVE-2020-10684
published 2020-03-24CVE-2020-10684: A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of…
PriorityP180high7.1CVSS 3.1
AVLACLPRLUINSUCNIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
0.34%
26.7th percentile
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 2.9.7+dfsg-1 (bookworm) | ansible 2.9.7+dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| redhat | ansible | >= 0 < 2.9.7+dfsg-1 | 2.9.7+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.7+dfsg-1 | 2.9.7+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.7+dfsg-1 | 2.9.7+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.7+dfsg-1 | 2.9.7+dfsg-1 |
| redhat | ansible | >= 2.7.0 < 2.7.17 | 2.7.17 |
| redhat | ansible | >= 2.7.0a1 < 2.7.17 | 2.7.17 |
| redhat | ansible | >= 2.8.0 < 2.8.9 | 2.8.9 |
| redhat | ansible | >= 2.8.0a1 < 2.8.11 | 2.8.11 |
| redhat | ansible | >= 2.9.0 < 2.9.6 | 2.9.6 |
| redhat | ansible | >= 2.9.0a1 < 2.9.7 | 2.9.7 |
| redhat | ansible_tower | <= 3.3.5 | — |
| redhat | ansible_tower | 3.5.0 – 3.5.5 | — |
| redhat | ansible_tower | 3.6.0 – 3.6.3 | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered when `ansible_facts` is used as a subkey of itself with `inject` enabled, allowing overwrite of ansible_facts after the clean phase — monitor playbooks or roles that set `ansible_facts` as a subkey of itself combined with inject=True ↗
- →Attacker-controlled ansible_facts keys such as `ansible_hosts` and `users` are indicators of exploitation — audit fact values for unexpected or attacker-supplied content in these keys ↗
- →Upstream fix is available at the referenced GitHub pull request — use it as a reference for code-level detection or patching verification ↗
- ·All Ansible Engine 2.7.x, 2.8.x, and 2.9.x versions prior to 2.7.17, 2.8.9, and 2.9.6 respectively are affected; upgrade to fixed versions to remediate ↗
- ·Ansible Tower versions 3.4.5, 3.5.5, and 3.6.3 and earlier are also affected ↗
- ·The only known mitigation is to avoid using ansible_facts as a subkey entirely; no other workaround exists ↗
- ·RHOSP packages the affected code but does not use ansible_facts as a subkey directly, reducing its exposure; no RHOSP update is planned ↗
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv7.1HIGH
vulncheck7.9HIGH
vendor_debian7.9HIGH
vendor_redhat7.9HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Ansible: code injection when using ansible_facts as a subkey
vendor_redhat·2020-03-23·CVSS 7.9
CVE-2020-10684 [HIGH] CWE-862 Ansible: code injection when using ansible_facts as a subkey
Ansible: code injection when using ansible_facts as a subkey
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.
A flaw was found in the Ansible Engine. When using ansible_facts as a subkey of itself, and promoting it to a variable when injecting is enabled, overwriting the ansible_facts after the clean, an attacker could take advantage of this by altering the ansible_facts leading to privileg
Debian
CVE-2020-10684: ansible - A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to...
vendor_debian·2020·CVSS 7.9
CVE-2020-10684 [HIGH] CVE-2020-10684: ansible - A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to...
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.
Scope: local
bookworm: resolved (fixed in 2.9.7+dfsg-1)
bullseye: resolved (fixed in 2.9.7+dfsg-1)
forky: resolved (fixed in 2.9.7+dfsg-1)
sid: resolved (fixed in 2.9.7+dfsg-1)
trixie: resolved (fixed in 2.9.7+dfsg-1)
GHSA
Code Injection, Race Condition, and Execution with Unnecessary Privileges in Ansible
ghsa·2021-04-07
CVE-2020-10684 [MEDIUM] CWE-250 Code Injection, Race Condition, and Execution with Unnecessary Privileges in Ansible
Code Injection, Race Condition, and Execution with Unnecessary Privileges in Ansible
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.11, and 2.9.7 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.
OSV
Code Injection, Race Condition, and Execution with Unnecessary Privileges in Ansible
osv·2021-04-07
CVE-2020-10684 [MEDIUM] Code Injection, Race Condition, and Execution with Unnecessary Privileges in Ansible
Code Injection, Race Condition, and Execution with Unnecessary Privileges in Ansible
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.11, and 2.9.7 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.
OSV
CVE-2020-10684: A flaw was found in Ansible Engine, all versions 2
osv·2020-03-24·CVSS 7.1
CVE-2020-10684 [HIGH] CVE-2020-10684: A flaw was found in Ansible Engine, all versions 2
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.
VulnCheck
Red Hat ansible Improper Control of Generation of Code ('Code Injection')
vulncheck·2020·CVSS 7.9
CVE-2020-10684 [HIGH] Red Hat ansible Improper Control of Generation of Code ('Code Injection')
Red Hat ansible Improper Control of Generation of Code ('Code Injection')
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.
Affected: Red Hat ansible
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://1665891.fs1.hubspotusercontent-na1.net/hubfs/1665891/
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10684 ansible: code injection when using ansible_facts as a subkey [openstack-rdo]
bugzilla·2020-03-23·CVSS 7.9
CVE-2020-10684 [HIGH] CVE-2020-10684 ansible: code injection when using ansible_facts as a subkey [openstack-rdo]
CVE-2020-10684 ansible: code injection when using ansible_facts as a subkey [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Fixed by update to 2.8
Bugzilla
CVE-2020-10684 ansible: code injection when using ansible_facts as a subkey [epel-all]
bugzilla·2020-03-23·CVSS 7.9
CVE-2020-10684 [HIGH] CVE-2020-10684 ansible: code injection when using ansible_facts as a subkey [epel-all]
CVE-2020-10684 ansible: code injection when using ansible_facts as a subkey [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2020-10684 ansible: code injection when using ansible_facts as a subkey [fedora-all]
bugzilla·2020-03-23·CVSS 7.9
CVE-2020-10684 [HIGH] CVE-2020-10684 ansible: code injection when using ansible_facts as a subkey [fedora-all]
CVE-2020-10684 ansible: code injection when using ansible_facts as a subkey [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
Bugzilla
CVE-2020-10684 Ansible: code injection when using ansible_facts as a subkey
bugzilla·2020-03-20·CVSS 7.9
CVE-2020-10684 [HIGH] CVE-2020-10684 Ansible: code injection when using ansible_facts as a subkey
CVE-2020-10684 Ansible: code injection when using ansible_facts as a subkey
Keys for ansible_facts can be overwritten when ansible_facts is added itself as a subkey. This action would happen after cleaning with unprocessed subkeys, as ansible_facts could be added as a subkey.
Discussion:
Acknowledgments:
Name: Damien Aumaitre (Quarkslab), Nicolas Surbayrole (Quarkslab)
---
Mitigation:
Currently, there is not a known mitigation except avoiding the functionality of using ansible_facts as a subkey.
---
I am confused by that statement. Ansible Tower also does not maintain its own version of Ansible.
---
Created ansible tracking bugs for this issue:
Affects: openstack-rdo [bug 1816309]
---
Created ansible tracking bugs for this issue:
Affects: epel-all [bug 1816311]
Affects: fedo
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10684https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DKPA4KC3OJSUFASUYMG66HKJE7ADNGFW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRRYUU5ZBLPBXCYG6CFP35D64NP2UB2S/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WQVOQD4VAIXXTVQAJKTN7NUGTJFE2PCB/https://security.gentoo.org/glsa/202006-11https://www.debian.org/security/2021/dsa-4950https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10684https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DKPA4KC3OJSUFASUYMG66HKJE7ADNGFW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRRYUU5ZBLPBXCYG6CFP35D64NP2UB2S/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WQVOQD4VAIXXTVQAJKTN7NUGTJFE2PCB/https://security.gentoo.org/glsa/202006-11https://www.debian.org/security/2021/dsa-4950
2020-03-24
Published
Exploited in the wild