CVE-2020-1736
published 2020-03-16CVE-2020-1736: A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files…
PriorityP411low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.40%
32.8th percentile
A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be changed to have less restrictive permissions before the move. This could lead to the disclosure of sensitive data. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| red_hat | ansible | — | — |
| redhat | ansible | <= 2.7.16 | — |
| redhat | ansible | 2.7.0 – 2.10.0 | — |
| redhat | ansible | >= 2.8.0 < 2.8.15 | 2.8.15 |
| redhat | ansible | >= 2.9.0 < 2.9.13 | 2.9.13 |
| redhat | ansible_tower | <= 3.3.4 | — |
| redhat | ansible_tower | 3.3.5 – 3.4.5 | — |
| redhat | ansible_tower | 3.5.0 – 3.5.5 | — |
| redhat | ansible_tower | 3.6.0 – 3.6.3 | — |
| redhat | ansible_tower | 3.7.0 – 3.7.2 | — |
| redhat | cloudforms_management_engine | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv3.3LOW
vendor_debian2.2LOW
vendor_redhat2.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ansible: atomic_move primitive sets permissive permissions
vendor_redhat·2020-02-18·CVSS 2.2
CVE-2020-1736 [LOW] CWE-732 ansible: atomic_move primitive sets permissive permissions
ansible: atomic_move primitive sets permissive permissions
A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be changed to have less restrictive permissions before the move. This could lead to the disclosure of sensitive data. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be changed to have less restrictive permissions
Debian
CVE-2020-1736: ansible - A flaw was found in Ansible Engine when a file is moved using atomic_move primit...
vendor_debian·2020·CVSS 2.2
CVE-2020-1736 [LOW] CVE-2020-1736: ansible - A flaw was found in Ansible Engine when a file is moved using atomic_move primit...
A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be changed to have less restrictive permissions before the move. This could lead to the disclosure of sensitive data. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
Incorrect Permission Assignment for Critical Resource in Ansible
ghsa·2022-02-09
CVE-2020-1736 [MEDIUM] CWE-732 Incorrect Permission Assignment for Critical Resource in Ansible
Incorrect Permission Assignment for Critical Resource in Ansible
A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be changed to have less restrictive permissions before the move. This could lead to the disclosure of sensitive data. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
OSV
Incorrect Permission Assignment for Critical Resource in Ansible
osv·2022-02-09
CVE-2020-1736 [MEDIUM] Incorrect Permission Assignment for Critical Resource in Ansible
Incorrect Permission Assignment for Critical Resource in Ansible
A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be changed to have less restrictive permissions before the move. This could lead to the disclosure of sensitive data. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
OSV
CVE-2020-1736: A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified
osv·2020-03-16·CVSS 3.3
CVE-2020-1736 [LOW] CVE-2020-1736: A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified
A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be changed to have less restrictive permissions before the move. This could lead to the disclosure of sensitive data. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-1736 ansible: atomic_move primitive sets permissive permissions [openstack-rdo]
bugzilla·2020-02-27·CVSS 2.2
CVE-2020-1736 [LOW] CVE-2020-1736 ansible: atomic_move primitive sets permissive permissions [openstack-rdo]
CVE-2020-1736 ansible: atomic_move primitive sets permissive permissions [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Fixed by update to 2.8.10
Bugzilla
CVE-2020-1736 ansible: atomic_move primitive sets permissive permissions [fedora-all]
bugzilla·2020-02-20·CVSS 2.2
CVE-2020-1736 [LOW] CVE-2020-1736 ansible: atomic_move primitive sets permissive permissions [fedora-all]
CVE-2020-1736 ansible: atomic_move primitive sets permissive permissions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2020-1736 ansible: atomic_move primitive sets permissive permissions [epel-all]
bugzilla·2020-02-20·CVSS 2.2
CVE-2020-1736 [LOW] CVE-2020-1736 ansible: atomic_move primitive sets permissive permissions [epel-all]
CVE-2020-1736 ansible: atomic_move primitive sets permissive permissions [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
Bugzilla
CVE-2020-1736 ansible: atomic_move primitive sets permissive permissions
bugzilla·2020-02-12·CVSS 2.2
CVE-2020-1736 [LOW] CVE-2020-1736 ansible: atomic_move primitive sets permissive permissions
CVE-2020-1736 ansible: atomic_move primitive sets permissive permissions
The atomic_move primitive is lacking moving files with a mode. This sets the destination files world-readable if the destination file does not exist and if the file exists could become with less restricted permissions before the move. This could lead in disclosing sensitive data.
Discussion:
Acknowledgments:
Name: Damien Aumaitre (Quarkslab), Nicolas Surbayrole (Quarkslab)
---
Any upstream reference for the issue available?
---
Created ansible tracking bugs for this issue:
Affects: epel-all [bug 1805332]
Affects: fedora-all [bug 1805331]
---
Hey Salvatore, I am working to provide additional information regarding this issue; more details as you requested, affected versions as well as upstream links in case w
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1736https://github.com/ansible/ansible/issues/67794https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2NYYQP2XJB2TTRP6AKWVMBSPB2DFJNKD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BPNZWBAUP4ZHUR6PO7U6ZXEKNCX62KZ7/https://security.gentoo.org/glsa/202006-11https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1736https://github.com/ansible/ansible/issues/67794https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2NYYQP2XJB2TTRP6AKWVMBSPB2DFJNKD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BPNZWBAUP4ZHUR6PO7U6ZXEKNCX62KZ7/https://security.gentoo.org/glsa/202006-11
2020-03-16
Published