CVE-2020-14365
published 2020-09-23CVE-2020-14365: A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf…
PriorityP433high7.1CVSS 3.1
AVLACLPRLUINSUCNIHAH
EPSS
0.23%
14.3th percentile
A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 2.9.13+dfsg-1 (bookworm) | ansible 2.9.13+dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
| redhat | ansible | >= 0 < 2.9.13+dfsg-1 | 2.9.13+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.13+dfsg-1 | 2.9.13+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.13+dfsg-1 | 2.9.13+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.13+dfsg-1 | 2.9.13+dfsg-1 |
| redhat | ansible | >= 2.8.0a1 < 2.8.15 | 2.8.15 |
| redhat | ansible | >= 2.9.0a1 < 2.9.13 | 2.9.13 |
| redhat | ansible_engine | — | — |
| redhat | ansible_engine | 2.8.0 – 2.8.15 | — |
| redhat | ansible_engine | 2.9.0 – 2.9.13 | — |
| redhat | ansible_tower | — | — |
| redhat | ansible_tower | 3.6.0 – 3.6.5 | — |
| redhat | ansible_tower | 3.7.0 – 3.7.2 | — |
| redhat | ceph_storage | — | — |
| redhat | ceph_storage | — | — |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv2.06.6MEDIUMAV:L/AC:L/Au:N/C:N/I:C/A:C
osv7.1HIGH
vendor_debian7.1LOW
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ansible: dnf module install packages with no GPG signature
vendor_redhat·2020-08-31·CVSS 7.1
CVE-2020-14365 [HIGH] CWE-347 ansible: dnf module install packages with no GPG signature
ansible: dnf module install packages with no GPG signature
A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.
A flaw was found in the Ansible Engine when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious
Debian
CVE-2020-14365: ansible - A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 an...
vendor_debian·2020·CVSS 7.1
CVE-2020-14365 [HIGH] CVE-2020-14365: ansible - A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 an...
A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.
Scope: local
bookworm: resolved (fixed in 2.9.13+dfsg-1)
bullseye: resolved (fixed in 2.9.13+dfsg-1)
forky: resolved (fixed in 2.9.13+dfsg-1)
sid: resolved (fixed in 2.9.13+dfsg-1)
trixie: resolved (fixed in 2.9.13+dfsg-1)
OSV
Improper Verification of Cryptographic Signature in ansible
osv·2021-04-20
CVE-2020-14365 [MEDIUM] Improper Verification of Cryptographic Signature in ansible
Improper Verification of Cryptographic Signature in ansible
A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when `disable_gpg_check` is set to `False`, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.
GHSA
Improper Verification of Cryptographic Signature in ansible
ghsa·2021-04-20
CVE-2020-14365 [MEDIUM] CWE-347 Improper Verification of Cryptographic Signature in ansible
Improper Verification of Cryptographic Signature in ansible
A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when `disable_gpg_check` is set to `False`, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.
OSV
CVE-2020-14365: A flaw was found in the Ansible Engine, in ansible-engine 2
osv·2020-09-23·CVSS 7.1
CVE-2020-14365 [HIGH] CVE-2020-14365: A flaw was found in the Ansible Engine, in ansible-engine 2
A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.
No detection rules found.
No public exploits indexed.
2020-09-23
Published