cbcvebase.
CVE-2020-1735
published 2020-03-16

CVE-2020-1735: A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new…

medium4.6CVSS 3.1
AVLACLPRHUINSCCLILAN
A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianansible< ansible 2.9.7+dfsg-1 (bookworm)ansible 2.9.7+dfsg-1 (bookworm)
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
red_hatansible
redhatansible< 2.7.172.7.17
redhatansible>= 0 < 2.9.7+dfsg-12.9.7+dfsg-1
redhatansible>= 0 < 2.9.7+dfsg-12.9.7+dfsg-1
redhatansible>= 0 < 2.9.7+dfsg-12.9.7+dfsg-1
redhatansible>= 0 < 2.9.7+dfsg-12.9.7+dfsg-1
redhatansible>= 2.7.0a1 < 2.7.182.7.18
redhatansible>= 2.8.0 < 2.8.112.8.11
redhatansible>= 2.8.0a1 < 2.8.122.8.12
redhatansible>= 2.9.0 < 2.9.72.9.7
redhatansible>= 2.9.0a1 < 2.9.82.9.8
redhatansible_tower<= 3.3.4
redhatansible_tower3.3.5 – 3.4.5
redhatansible_tower3.5.0 – 3.5.5
redhatansible_tower3.6.0 – 3.6.3
redhatcloudforms_management_engine
redhatopenstack

CVSS provenance

nvdv3.14.6MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
osv4.6MEDIUM