CVE-2020-1734
published 2020-03-03CVE-2020-1734: A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by…
PriorityP336high7.4CVSS 3.1
AVLACHPRLUIRSCCHIHAL
EPSS
0.44%
35.9th percentile
A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could take advantage and run arbitrary commands by overwriting the ansible facts.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | — | — |
| red_hat | ansible | — | — |
| redhat | ansible | >= 0 < 2.8.13 | 2.8.13 |
| redhat | ansible | >= 2.10.0a1 < 2.10.0rc1 | 2.10.0rc1 |
| redhat | ansible | >= 2.9.0a1 < 2.9.11 | 2.9.11 |
| redhat | ansible_engine | <= 2.7.16 | — |
| redhat | ansible_engine | — | — |
| redhat | ansible_engine | — | — |
| redhat | ansible_tower | <= 3.3.4 | — |
| redhat | ansible_tower | — | — |
| redhat | ansible_tower | — | — |
| redhat | ansible_tower | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L
nvdv2.03.7LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
osv7.4HIGH
vendor_debian7.4LOW
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OS Command Injection in ansible
ghsa·2022-02-09
CVE-2020-1734 [HIGH] CWE-78 OS Command Injection in ansible
OS Command Injection in ansible
A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses `subprocess.Popen()` with `shell=True`, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could take advantage and run arbitrary commands by overwriting the ansible facts.
OSV
OS Command Injection in ansible
osv·2022-02-09
CVE-2020-1734 [HIGH] OS Command Injection in ansible
OS Command Injection in ansible
A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses `subprocess.Popen()` with `shell=True`, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could take advantage and run arbitrary commands by overwriting the ansible facts.
OSV
CVE-2020-1734: A flaw was found in the pipe lookup plugin of ansible
osv·2020-03-03·CVSS 7.4
CVE-2020-1734 [HIGH] CVE-2020-1734: A flaw was found in the pipe lookup plugin of ansible
A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could take advantage and run arbitrary commands by overwriting the ansible facts.
Red Hat
ansible: shell enabled by default in a pipe lookup plugin subprocess
vendor_redhat·2020-02-18·CVSS 7.4
CVE-2020-1734 [HIGH] CWE-78 ansible: shell enabled by default in a pipe lookup plugin subprocess
ansible: shell enabled by default in a pipe lookup plugin subprocess
A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could take advantage and run arbitrary commands by overwriting the ansible facts.
A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could take advantage and run arbitrary commands by overwriting the ansible facts.
Statement: Ansible Engine 2.7.16, 2.8.10, and 2.9.6 as well as previous ve
Debian
CVE-2020-1734: ansible - A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be...
vendor_debian·2020·CVSS 7.4
CVE-2020-1734 [HIGH] CVE-2020-1734: ansible - A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be...
A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could take advantage and run arbitrary commands by overwriting the ansible facts.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-27766 ImageMagick: outside the range of representable values of type 'unsigned long' at MagickCore/statistic.c
bugzilla·2020-11-04·CVSS 7.8
CVE-2020-27766 [HIGH] CVE-2020-27766 ImageMagick: outside the range of representable values of type 'unsigned long' at MagickCore/statistic.c
CVE-2020-27766 ImageMagick: outside the range of representable values of type 'unsigned long' at MagickCore/statistic.c
In ImageMagick, there is an outside the range of representable values of type 'unsigned long' at MagickCore/statistic.c.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1734
Discussion:
Acknowledgments:
Name: Suhwan Song (Seoul National University)
---
Statement:
This flaw is out of support scope for Red Hat Enterprise Linux 5, 6, and 7. Inkscape is not affected because it no longer uses a bundled ImageMagick in Red Hat Enterprise Linux 8. For more information regarding support scopes, please see https://access.redhat.com/support/policy/updates/errata .
---
Red Hat Product Security marked this as Low severity because although it could potentially le
Bugzilla
CVE-2020-1734 ansible: shell enabled by default in a pipe lookup plugin subprocess [openstack-rdo]
bugzilla·2020-02-27·CVSS 7.4
CVE-2020-1734 [HIGH] CVE-2020-1734 ansible: shell enabled by default in a pipe lookup plugin subprocess [openstack-rdo]
CVE-2020-1734 ansible: shell enabled by default in a pipe lookup plugin subprocess [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Fixed by update
Bugzilla
CVE-2020-1734 ansible: shell enabled by default in a pipe lookup plugin subprocess [fedora-all]
bugzilla·2020-02-20·CVSS 7.4
CVE-2020-1734 [HIGH] CVE-2020-1734 ansible: shell enabled by default in a pipe lookup plugin subprocess [fedora-all]
CVE-2020-1734 ansible: shell enabled by default in a pipe lookup plugin subprocess [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2020-1734 ansible: shell enabled by default in a pipe lookup plugin subprocess [epel-all]
bugzilla·2020-02-20·CVSS 7.4
CVE-2020-1734 [HIGH] CVE-2020-1734 ansible: shell enabled by default in a pipe lookup plugin subprocess [epel-all]
CVE-2020-1734 ansible: shell enabled by default in a pipe lookup plugin subprocess [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2020-1734 ansible: shell enabled by default in a pipe lookup plugin subprocess
bugzilla·2020-02-11·CVSS 7.4
CVE-2020-1734 [HIGH] CVE-2020-1734 ansible: shell enabled by default in a pipe lookup plugin subprocess
CVE-2020-1734 ansible: shell enabled by default in a pipe lookup plugin subprocess
The pipe lookup plugin uses subprocess.Popen() with shell=True. This can be used to run arbitrary commands by overwriting ansible facts and the variable is not escaped by quote plugin.
Discussion:
Acknowledgments:
Name: Damien Aumaitre (Quarkslab), Nicolas Surbayrole (Quarkslab)
---
Created ansible tracking bugs for this issue:
Affects: epel-all [bug 1805339]
Affects: fedora-all [bug 1805338]
---
Working to provide additional information regarding this issue; more details as you requested, affected versions as well as upstream links in case we already have. Prioritising this for now.
---
This was already reported (see https://github.com/ansible/ansible/issues/6550) but not fixed. The suggested cor
2020-03-03
Published