CVE-2020-25635
published 2020-10-05CVE-2020-25635: A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed. Files would…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.32%
23.9th percentile
A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed. Files would remain in the bucket exposing the data. This issue affects directly data confidentiality.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| aws_community | community_collections | — | — |
| debian | ansible | — | — |
| redhat | ansible | — | — |
| redhat | ansible | >= 0 < 2.10.1 | 2.10.1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Collections: aws_ssm connection plugin should garbage collect the s3 bucket after the file transfers
vendor_redhat·2020-09-04·CVSS 5.0
CVE-2020-25635 [MEDIUM] CWE-212 Collections: aws_ssm connection plugin should garbage collect the s3 bucket after the file transfers
Collections: aws_ssm connection plugin should garbage collect the s3 bucket after the file transfers
A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed. Files would remain in the bucket exposing the data. This issue affects directly data confidentiality.
A flaw was found in Ansible Base. When using the aws_ssm connection plugin as a garbage collector, it is not working after the playbook run is completed due to the file remaining in the bucket, which exposes the data. The highest threat from this vulnerability is to confidentiality.
Statement: Ansible collection aws_ssm connection community plugin 1.2.1 and previous versions until 1.0.0 when it was introduced to this plugin, are the versions aff
Debian
CVE-2020-25635: ansible - A flaw was found in Ansible Base when using the aws_ssm connection plugin as gar...
vendor_debian·2020·CVSS 5.0
CVE-2020-25635 [MEDIUM] CVE-2020-25635: ansible - A flaw was found in Ansible Base when using the aws_ssm connection plugin as gar...
A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed. Files would remain in the bucket exposing the data. This issue affects directly data confidentiality.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
Ansible does not collect garbage after playbook run
ghsa·2025-10-31
CVE-2020-25635 [MEDIUM] CWE-212 Ansible does not collect garbage after playbook run
Ansible does not collect garbage after playbook run
A flaw was found in Ansible Base when using the aws_ssm connection plugin as its garbage collector is not happening after the playbook run is completed. Files would remain in the bucket exposing the data. This issue directly affects data confidentiality.
OSV
Ansible does not collect garbage after playbook run
osv·2025-10-31
CVE-2020-25635 [MEDIUM] Ansible does not collect garbage after playbook run
Ansible does not collect garbage after playbook run
A flaw was found in Ansible Base when using the aws_ssm connection plugin as its garbage collector is not happening after the playbook run is completed. Files would remain in the bucket exposing the data. This issue directly affects data confidentiality.
OSV
CVE-2020-25635: A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed
osv·2020-10-05
CVE-2020-25635 CVE-2020-25635: A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed
A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed. Files would remain in the bucket exposing the data. This issue affects directly data confidentiality.
No detection rules found.
No public exploits indexed.
2020-10-05
Published