Description
A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
References (7)
Core 7
Core References
Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1735
Exploit, Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://github.com/ansible/ansible/issues/67793
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WQVOQD4VAIXXTVQAJKTN7NUGTJFE2PCB/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DKPA4KC3OJSUFASUYMG66HKJE7ADNGFW/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRRYUU5ZBLPBXCYG6CFP35D64NP2UB2S/
Third Party Advisory vendor-advisory
x_refsource_gentoo
https://security.gentoo.org/glsa/202006-11
Third Party Advisory vendor-advisory
x_refsource_debian
https://www.debian.org/security/2021/dsa-4950
Scores
CVSS v3
4.2
EPSS
0.0014
EPSS Percentile
33.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-22
Status
published
Products (9)
debian/debian_linux
10.0
fedoraproject/fedora
30
fedoraproject/fedora
31
fedoraproject/fedora
32
pypi/ansible
2.7.0a1 - 2.7.18PyPI
redhat/ansible
< 2.7.17
redhat/ansible_tower
< 3.3.4
redhat/cloudforms_management_engine
5.0
redhat/openstack
13
Published
Mar 16, 2020
Tracked Since
Feb 18, 2026