CVE-2020-10684

HIGH EXPLOITED IN THE WILD

Ansible Engine <2.7.17, 2.8.9, 2.9.6 - Privilege Escalation/Code In...

Title source: llm

Description

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.

Scores

CVSS v3 7.9
EPSS 0.0002
EPSS Percentile 6.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H

Exploitation Intel

VulnCheck KEV 2024-05-10
InTheWild.io 2024-05-17

Classification

CWE
CWE-862 CWE-362 CWE-94
Status published

Affected Products (9)

redhat/ansible < 2.7.17
redhat/ansible_tower < 3.3.5
redhat/openstack
redhat/openstack
debian/debian_linux
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
pypi/ansible < 2.7.17PyPI

Timeline

Published Mar 24, 2020
Tracked Since Feb 18, 2026