← Back

CVE-2020-14365

nvd nist
Published: Sep 23, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Exploitability: 1.8 / Impact: 5.2
Source: NVD

Description

A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.

Affected (10)

4 products
Ansible Engine
Ansible Tower
Ceph Storage
Openstack Platform
1 product
Debian Linux
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
From 2.8.0 to 2.8.15
From 2.9.0 to 2.9.13
Redhat
From 3.6.0 to 3.6.5
From 3.7.0 to 3.7.2
Version 3.0
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 2.0
Version 3.0
Redhat
Version 10.0
Version 13.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0

References (4)

Source: secalert@redhat.com
Issue TrackingVendor Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.