← Back

CVE-2020-1739

nvd nist
Published: Mar 12, 2020Modified: Nov 21, 2024

JSON object

Loading...
3.9
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Exploitability: 1.3 / Impact: 2.5
Source: NVD

Description

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

Affected (14)

4 products
Ansible
Ansible Tower
Cloudforms Management Engine
Openstack
1 product
Fedora
1 product
Debian Linux
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Up to 2.7.16
From 2.8.0 to 2.8.8
From 2.9.0 to 2.9.5
Redhat
Up to 3.3.4
From 3.4.0 to 3.4.5
From 3.5.0 to 3.5.5
From 3.6.0 to 3.6.3
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 5.0
Version 13
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 30
Version 31
Version 32
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 8.0

References (14)

Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.