cbcvebase.
CVE-2020-10744
published 2020-05-15

CVE-2020-10744: An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The…

PriorityP421medium5CVSS 3.1
AVLACHPRLUIRSCCLILAL
EPSS
0.26%
17.1th percentile
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianansible< ansible 2.9.13+dfsg-1 (bookworm)ansible 2.9.13+dfsg-1 (bookworm)
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_ansible_2.9.18-1_on_cbl_mariner_1.0
red_hatansible
red_hatansible
red_hatansible
red_hatansible
red_hatansible
red_hatansible
redhatansible>= 0 < 2.9.13+dfsg-12.9.13+dfsg-1
redhatansible>= 0 < 2.9.13+dfsg-12.9.13+dfsg-1
redhatansible>= 0 < 2.9.13+dfsg-12.9.13+dfsg-1
redhatansible>= 0 < 2.9.13+dfsg-12.9.13+dfsg-1
redhatansible>= 0 < 2.9.122.9.12
redhatansible>= 0 < 2.0.0.2-2ubuntu1.3+esm12.0.0.2-2ubuntu1.3+esm1
redhatansible>= 0 < 2.5.1+dfsg-1ubuntu0.1+esm12.5.1+dfsg-1ubuntu0.1+esm1
redhatansible>= 0 < 2.9.6+dfsg-1ubuntu0.1~esm12.9.6+dfsg-1ubuntu0.1~esm1
redhatansible>= 0 < 2.10.7+merged+base+2.10.8+dfsg-1ubuntu0.1~esm12.10.7+merged+base+2.10.8+dfsg-1ubuntu0.1~esm1
redhatansible>= 2.10.0a1 < 2.10.0rc12.10.0rc1
redhatansible2.7.0 – 2.7.18
redhatansible2.8.0 – 2.8.12
redhatansible2.9.0 – 2.9.9
redhatansible_tower3.4.0 – 3.4.5
redhatansible_tower3.5.0 – 3.5.6

CVSS provenance

nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
nvdv2.03.7LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
ghsa5.0MEDIUM
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_msrc5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.