CVE-2020-1740
published 2020-03-16CVE-2020-1740: A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same…
PriorityP421medium4.7CVSS 3.1
AVLACHPRLUINSUCHINAN
EPSS
0.37%
29.7th percentile
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp and the returned file descriptor is closed and the method write_data is called to write the existing secret in the file. This method will delete the file before recreating it insecurely. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 2.9.7+dfsg-1 (bookworm) | ansible 2.9.7+dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| red_hat | ansible | — | — |
| redhat | ansible | < 2.7.17 | 2.7.17 |
| redhat | ansible | >= 0 < 2.9.7+dfsg-1 | 2.9.7+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.7+dfsg-1 | 2.9.7+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.7+dfsg-1 | 2.9.7+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.7+dfsg-1 | 2.9.7+dfsg-1 |
| redhat | ansible | >= 0 < 2.7.17 | 2.7.17 |
| redhat | ansible | >= 2.8.0 < 2.8.11 | 2.8.11 |
| redhat | ansible | >= 2.8.0a1 < 2.8.11 | 2.8.11 |
| redhat | ansible | >= 2.9.0 < 2.9.7 | 2.9.7 |
| redhat | ansible | >= 2.9.0a1 < 2.9.7 | 2.9.7 |
| redhat | ansible_tower | <= 3.3.4 | — |
| redhat | ansible_tower | 3.3.5 – 3.4.5 | — |
| redhat | ansible_tower | 3.5.0 – 3.5.5 | — |
| redhat | ansible_tower | 3.6.0 – 3.6.3 | — |
| redhat | cloudforms_management_engine | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv4.7MEDIUM
vendor_debian3.9LOW
vendor_redhat3.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Exposure of Sensitive Information to an Unauthorized Actor and Insecure Temporary File in Ansible
osv·2021-04-07
CVE-2020-1740 [MEDIUM] Exposure of Sensitive Information to an Unauthorized Actor and Insecure Temporary File in Ansible
Exposure of Sensitive Information to an Unauthorized Actor and Insecure Temporary File in Ansible
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp and the returned file descriptor is closed and the method write_data is called to write the existing secret in the file. This method will delete the file before recreating it insecurely. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor and Insecure Temporary File in Ansible
ghsa·2021-04-07
CVE-2020-1740 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor and Insecure Temporary File in Ansible
Exposure of Sensitive Information to an Unauthorized Actor and Insecure Temporary File in Ansible
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp and the returned file descriptor is closed and the method write_data is called to write the existing secret in the file. This method will delete the file before recreating it insecurely. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
OSV
CVE-2020-1740: A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files
osv·2020-03-16·CVSS 4.7
CVE-2020-1740 [MEDIUM] CVE-2020-1740: A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp and the returned file descriptor is closed and the method write_data is called to write the existing secret in the file. This method will delete the file before recreating it insecurely. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
Red Hat
ansible: secrets readable after ansible-vault edit
vendor_redhat·2020-02-18·CVSS 3.9
CVE-2020-1740 [LOW] CWE-377 ansible: secrets readable after ansible-vault edit
ansible: secrets readable after ansible-vault edit
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp and the returned file descriptor is closed and the method write_data is called to write the existing secret in the file. This method will delete the file before recreating it insecurely. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a temporary f
Debian
CVE-2020-1740: ansible - A flaw was found in Ansible Engine when using Ansible Vault for editing encrypte...
vendor_debian·2020·CVSS 3.9
CVE-2020-1740 [LOW] CVE-2020-1740: ansible - A flaw was found in Ansible Engine when using Ansible Vault for editing encrypte...
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp and the returned file descriptor is closed and the method write_data is called to write the existing secret in the file. This method will delete the file before recreating it insecurely. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
Scope: local
bookworm: resolved (fixed in 2.9.7+dfsg-1)
bullseye: resolved (fixed in 2.9.7+dfsg-1)
forky: resolved (fixed in 2.9.7+dfsg-1)
sid: resolved (fixed in 2.9.7+dfsg-1)
trixie: resolved (fixed in 2.9.7+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-27769 ImageMagick: outside the range of representable values of type 'float' at MagickCore/quantize.c
bugzilla·2020-11-04·CVSS 3.3
CVE-2020-27769 [LOW] CVE-2020-27769 ImageMagick: outside the range of representable values of type 'float' at MagickCore/quantize.c
CVE-2020-27769 ImageMagick: outside the range of representable values of type 'float' at MagickCore/quantize.c
In ImageMagick, there are outside the range of representable values of type 'float' at MagickCore/quantize.c.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1740
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/7b058696133c6d36e0b48a454e357482db71982e
Discussion:
Acknowledgments:
Name: Suhwan Song (Seoul National University)
---
The patch addresses several occurrences in `PosterizeImage()`. Red Hat Product Security marked this as Low severity because although it could potentially lead to an impact to application availability, no specific impact was demonstrated in this case.
---
Statement:
This flaw is out of support scope for Red Hat Ente
Bugzilla
CVE-2020-1740 ansible: secrets readable after ansible-vault edit [openstack-rdo]
bugzilla·2020-02-27·CVSS 3.9
CVE-2020-1740 [LOW] CVE-2020-1740 ansible: secrets readable after ansible-vault edit [openstack-rdo]
CVE-2020-1740 ansible: secrets readable after ansible-vault edit [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Fixed by update to 2.8.10 in http
Bugzilla
CVE-2020-1740 ansible: secrets readable after ansible-vault edit [fedora-all]
bugzilla·2020-02-20·CVSS 3.9
CVE-2020-1740 [LOW] CVE-2020-1740 ansible: secrets readable after ansible-vault edit [fedora-all]
CVE-2020-1740 ansible: secrets readable after ansible-vault edit [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2020-1740 ansible: secrets readable after ansible-vault edit [epel-all]
bugzilla·2020-02-20·CVSS 3.9
CVE-2020-1740 [LOW] CVE-2020-1740 ansible: secrets readable after ansible-vault edit [epel-all]
CVE-2020-1740 ansible: secrets readable after ansible-vault edit [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2020-1735 ansible: path injection on dest parameter in fetch module
bugzilla·2020-02-12·CVSS 4.2
CVE-2020-1735 [MEDIUM] CVE-2020-1735 ansible: path injection on dest parameter in fetch module
CVE-2020-1735 ansible: path injection on dest parameter in fetch module
When using the fetch module, a path injection allows a remote user to choose the destination path on the controller node. This vulnerability could be an insufficient patch of CVE-2019-3828.
Discussion:
Acknowledgments:
Name: Damien Aumaitre (Quarkslab), Nicolas Surbayrole (Quarkslab)
---
Borja, I'm sorry I know I'm bit repetitive for all the respective issues for ansible CVE-2020-1735 up to CVE-2020-1740. It would be nice to get an idea for other downstream which versions are affected or if upstream is aware of those and working on fixes or if there are upstream issues to be tracked.
Any information on any of those? I have added NEEDINFO flags respectively for reach. Would it be possible to provide this further
Bugzilla
CVE-2020-1740 ansible: secrets readable after ansible-vault edit
bugzilla·2020-02-12·CVSS 3.9
CVE-2020-1740 [LOW] CVE-2020-1740 ansible: secrets readable after ansible-vault edit
CVE-2020-1740 ansible: secrets readable after ansible-vault edit
When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created a temporary file with mkstemp and the returned file descriptor is closed and the method write_data is called to write the existing secret in the file. This method will delete the file before recreate it insecurely.
Discussion:
Acknowledgments:
Name: Damien Aumaitre (Quarkslab), Nicolas Surbayrole (Quarkslab)
---
Is there any futher information on this issue? Is the issue reported upstream, which versions are affected?
---
Created ansible tracking bugs for this issue:
Affects: epel-all [bug 1805319]
Affects: fedora-all [bug 1805318]
---
Hey Salvatore, I am working to provide additional infor
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1740https://github.com/ansible/ansible/issues/67798https://lists.debian.org/debian-lts-announce/2020/05/msg00005.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DKPA4KC3OJSUFASUYMG66HKJE7ADNGFW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRRYUU5ZBLPBXCYG6CFP35D64NP2UB2S/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WQVOQD4VAIXXTVQAJKTN7NUGTJFE2PCB/https://security.gentoo.org/glsa/202006-11https://www.debian.org/security/2021/dsa-4950https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1740https://github.com/ansible/ansible/issues/67798https://lists.debian.org/debian-lts-announce/2020/05/msg00005.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DKPA4KC3OJSUFASUYMG66HKJE7ADNGFW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRRYUU5ZBLPBXCYG6CFP35D64NP2UB2S/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WQVOQD4VAIXXTVQAJKTN7NUGTJFE2PCB/https://security.gentoo.org/glsa/202006-11https://www.debian.org/security/2021/dsa-4950
2020-03-16
Published