CVE-2020-1735

MEDIUM

Ansible < 2.7.17 - Path Traversal via Fetch Module

Title source: llm
STIX 2.1

Description

A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

References (7)

Core 7
Core References
Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1735
Exploit, Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://github.com/ansible/ansible/issues/67793
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202006-11
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2021/dsa-4950

Scores

CVSS v3 4.2
EPSS 0.0014
EPSS Percentile 33.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-22
Status published
Products (9)
debian/debian_linux 10.0
fedoraproject/fedora 30
fedoraproject/fedora 31
fedoraproject/fedora 32
pypi/ansible 2.7.0a1 - 2.7.18PyPI
redhat/ansible < 2.7.17
redhat/ansible_tower < 3.3.4
redhat/cloudforms_management_engine 5.0
redhat/openstack 13
Published Mar 16, 2020
Tracked Since Feb 18, 2026