CVE-2020-1735

Aliases:GHSA-gfr2-qpxh-qj9mPYSEC-2020-7
Modified
Published: 16 Mar 2020, 15:05
Last modified:04 Aug 2024, 06:46

Vulnerability Summary

Overall Risk (default)
medium
28/100
CVSS Score
4.6 MEDIUM
v3.1 (nvd)
EPSS Score
0.14% LOW
0% probability -0.02%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

16 Mar 2020, 15:05
Published
Vulnerability first disclosed
04 Aug 2024, 06:46
Last Modified
Vulnerability information updated

Description

A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

CVSS Metrics

  • v4.0MEDIUMScore: 4.6CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
  • v3.1MEDIUMScore: 4.2CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
  • v3.1MEDIUMScore: 4.6CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
  • v2.0LOWScore: 3.6AV:L/AC:L/Au:N/C:P/I:P/A:N

EPSS Trends

Current EPSS score: 0.14% Percentile: 33%

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Affected Systems

  • debiandebian_linux

    10.0

  • fedoraprojectfedora

    30 | 31 | 32

  • PyPIansible

    ≥ 2.7.0a1, < 2.7.18 | ≥ 2.8.0a1, < 2.8.12 | ≥ 2.9.0a1, < 2.9.8 | ≥ 2.9.0, < 2.9.6

  • red hatansible

    2.7.x, 2.8.x, 2.9.x

  • redhatansible

    < 2.7.17 | ≥ 2.8.0, < 2.8.11 | ≥ 2.9.0, < 2.9.7

  • redhatansible_tower

    ≤ 3.3.4 | ≥ 3.3.5, ≤ 3.4.5 | ≥ 3.5.0, ≤ 3.5.5 | ≥ 3.6.0, ≤ 3.6.3

  • redhatcloudforms_management_engine

    5.0

  • redhatopenstack

    13

References (24)