cbcvebase.
CVE-2020-1735
published 2020-03-16

CVE-2020-1735: A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new…

PriorityP418medium4.6CVSS 3.1
AVLACLPRHUINSCCLILAN
EPSS
0.49%
39.4th percentile
A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianansible< ansible 2.9.7+dfsg-1 (bookworm)ansible 2.9.7+dfsg-1 (bookworm)
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
red_hatansible
redhatansible< 2.7.172.7.17
redhatansible>= 0 < 2.9.7+dfsg-12.9.7+dfsg-1
redhatansible>= 0 < 2.9.7+dfsg-12.9.7+dfsg-1
redhatansible>= 0 < 2.9.7+dfsg-12.9.7+dfsg-1
redhatansible>= 0 < 2.9.7+dfsg-12.9.7+dfsg-1
redhatansible>= 2.7.0a1 < 2.7.182.7.18
redhatansible>= 2.8.0 < 2.8.112.8.11
redhatansible>= 2.8.0a1 < 2.8.122.8.12
redhatansible>= 2.9.0 < 2.9.72.9.7
redhatansible>= 2.9.0a1 < 2.9.82.9.8
redhatansible_tower<= 3.3.4
redhatansible_tower3.3.5 – 3.4.5
redhatansible_tower3.5.0 – 3.5.5
redhatansible_tower3.6.0 – 3.6.3
redhatcloudforms_management_engine
redhatopenstack

CVSS provenance

nvdv3.14.6MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
osv4.6MEDIUM
vendor_debian4.2MEDIUM
vendor_redhat4.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.