CVE-2020-1739
LOWAnsible <2.7.16, <2.8.8, <2.9.5 - Info Disclosure
Title source: llmDescription
A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.
References (7)
Scores
CVSS v3
3.9
EPSS
0.0004
EPSS Percentile
13.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Classification
CWE
CWE-200
Status
published
Affected Products (10)
redhat/ansible
< 2.7.16
redhat/ansible_tower
< 3.3.4
redhat/cloudforms_management_engine
redhat/openstack
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
debian/debian_linux
debian/debian_linux
pypi/ansible
< 2.7.17PyPI
Timeline
Published
Mar 12, 2020
Tracked Since
Feb 18, 2026