CVE-2020-25636
published 2020-10-05CVE-2020-25636: A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are written directly to…
PriorityP431high7.1CVSS 3.1
AVLACLPRLUINSUCNIHAH
EPSS
0.30%
22.0th percentile
A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are written directly to the root bucket, making possible to have collisions when running multiple ansible processes. This issue affects mainly the service availability.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| aws_community | community_collections | — | — |
| debian | ansible | — | — |
| redhat | ansible | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv7.1HIGH
vendor_debian6.6LOW
vendor_redhat6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2020-25636: A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers
osv·2020-10-05·CVSS 7.1
CVE-2020-25636 [HIGH] CVE-2020-25636: A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers
A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are written directly to the root bucket, making possible to have collisions when running multiple ansible processes. This issue affects mainly the service availability.
Red Hat
Collections: aws_ssm connection plugin should namespace its file transfers
vendor_redhat·2020-09-04·CVSS 6.6
CVE-2020-25636 [MEDIUM] CWE-820 Collections: aws_ssm connection plugin should namespace its file transfers
Collections: aws_ssm connection plugin should namespace its file transfers
A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are written directly to the root bucket, making possible to have collisions when running multiple ansible processes. This issue affects mainly the service availability.
A flaw was found in Ansible Base when using the aws_ssm connection plugin, as there is not a namespace separation for file transfers. Files are written directly to the root bucket, making it possible to have collisions when running multiple Ansible processes. The highest threat from this vulnerability is to integrity and system availability.
Statement: Ansible collection aws_ssm connection community plugin 1.2.1 a
Debian
CVE-2020-25636: ansible - A flaw was found in Ansible Base when using the aws_ssm connection plugin as the...
vendor_debian·2020·CVSS 6.6
CVE-2020-25636 [MEDIUM] CVE-2020-25636: ansible - A flaw was found in Ansible Base when using the aws_ssm connection plugin as the...
A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are written directly to the root bucket, making possible to have collisions when running multiple ansible processes. This issue affects mainly the service availability.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
2020-10-05
Published