cbcvebase.
CVE-2020-1739
published 2020-03-12

CVE-2020-1739: A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is…

low3.9CVSS 3.1
AVLACLPRLUIRSUCLILAN
A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianansible< ansible 2.9.7+dfsg-1 (bookworm)ansible 2.9.7+dfsg-1 (bookworm)
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
red_hatansible
red_hatansible
red_hatansible
redhatansible<= 2.7.16
redhatansible>= 0 < 2.9.7+dfsg-12.9.7+dfsg-1
redhatansible>= 0 < 2.9.7+dfsg-12.9.7+dfsg-1
redhatansible>= 0 < 2.9.7+dfsg-12.9.7+dfsg-1
redhatansible>= 0 < 2.9.7+dfsg-12.9.7+dfsg-1
redhatansible>= 0 < 2.7.172.7.17
redhatansible>= 0 < 1.5.4+dfsg-1ubuntu0.1~esm31.5.4+dfsg-1ubuntu0.1~esm3
redhatansible>= 0 < 2.0.0.2-2ubuntu1.3+esm62.0.0.2-2ubuntu1.3+esm6
redhatansible>= 0 < 2.0.0.2-2ubuntu1.3+esm52.0.0.2-2ubuntu1.3+esm5
redhatansible>= 0 < 2.5.1+dfsg-1ubuntu0.1+esm52.5.1+dfsg-1ubuntu0.1+esm5
redhatansible>= 0 < 2.9.6+dfsg-1ubuntu0.1~esm32.9.6+dfsg-1ubuntu0.1~esm3
redhatansible2.8.0 – 2.8.8
redhatansible>= 2.8.0a1 < 2.8.112.8.11
redhatansible2.9.0 – 2.9.5
redhatansible>= 2.9.0a1 < 2.9.72.9.7
redhatansible_tower<= 3.3.4

CVSS provenance

nvdv3.13.9LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
osv4.3MEDIUM