CVE-2020-10684
HIGH EXPLOITED IN THE WILDAnsible Engine <2.7.17, 2.8.9, 2.9.6 - Privilege Escalation/Code In...
Title source: llmDescription
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.
References (6)
Scores
CVSS v3
7.9
EPSS
0.0002
EPSS Percentile
6.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H
Exploitation Intel
VulnCheck KEV
2024-05-10
InTheWild.io
2024-05-17
Classification
CWE
CWE-862
CWE-362
CWE-94
Status
published
Affected Products (9)
redhat/ansible
< 2.7.17
redhat/ansible_tower
< 3.3.5
redhat/openstack
redhat/openstack
debian/debian_linux
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
pypi/ansible
< 2.7.17PyPI
Timeline
Published
Mar 24, 2020
Tracked Since
Feb 18, 2026