CVE-2020-1739

Severity
3.9LOW
EPSS
0.0%
top 86.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 12
Latest updateMar 5

Description

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:NExploitability: 1.3 | Impact: 2.5

Affected Packages7 packages

PyPIansible2.8.0a12.8.11+2
Debianansible< 2.9.7+dfsg-1+3
NVDredhat/ansible2.8.02.8.8+2
NVDredhat/ansible_tower3.4.03.4.5+3
CVEListV5red_hat/ansible2.7.16 and prior, 2.8.8 and prior, 2.9.5 and prior+2

Also affects: Debian Linux 10.0, 8.0, Fedora 30, 31, 32

Patches

🔴Vulnerability Details

4
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Ansible2021-04-07
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Ansible2021-04-07
OSV
CVE-2020-1739: A flaw was found in Ansible 22020-03-12
CVEList
CVE-2020-1739: A flaw was found in Ansible 22020-03-12

📋Vendor Advisories

3
Ubuntu
Ansible vulnerabilities2025-03-05
Red Hat
ansible: svn module leaks password when specified as a parameter2020-02-18
Debian
CVE-2020-1739: ansible - A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and pri...2020

💬Community

5
Bugzilla
CVE-2020-2167 openshift/jenkins-plugin: Deserialization in snakeyaml YAML() objects allows for remote code execution2020-03-24
Bugzilla
CVE-2020-1739 ansible: svn module leaks password when specified as a parameter [openstack-rdo]2020-02-27
Bugzilla
CVE-2020-1739 ansible: svn module leaks password when specified as a parameter [epel-all]2020-02-20
Bugzilla
CVE-2020-1739 ansible: svn module leaks password when specified as a parameter [fedora-all]2020-02-20
Bugzilla
CVE-2020-1739 ansible: svn module leaks password when specified as a parameter2020-02-12