3.6
CVSSv2

CVE-2020-10684

Published: 24/03/2020 Updated: 07/11/2023
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x before 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openstack 10

redhat ansible tower

redhat ansible

redhat openstack 13

debian debian linux 10.0

fedoraproject fedora 30

fedoraproject fedora 31

fedoraproject fedora 32

Vendor Advisories

Several vulnerabilities have been found in Ansible, a configuration management, deployment and task execution system, which could result in information disclosure or argument injection In addition a race condition in become_user was fixed For the stable distribution (buster), these problems have been fixed in version 277+dfsg-1+deb10u1 We reco ...
Synopsis Important: Ansible security and bug fix update (297) Type/Severity Security Advisory: Important Topic An update for ansible is now available for Ansible Engine 29Red Hat Product Security has rated this update as having a security impactof Important A Common Vulnerability Scoring System (CVSS) b ...
Synopsis Important: Ansible security and bug fix update (297) Type/Severity Security Advisory: Important Topic An update for ansible is now available for Ansible Engine 2Red Hat Product Security has rated this update as having a security impactof Important A Common Vulnerability Scoring System (CVSS) bas ...
Synopsis Important: Ansible security and bug fix update (2811) Type/Severity Security Advisory: Important Topic An update for ansible is now available for Ansible Engine 28Red Hat Product Security has rated this update as having a security impactof Important A Common Vulnerability Scoring System (CVSS) ...
Synopsis Important: Ansible security and bug fix update (2717) Type/Severity Security Advisory: Important Topic An update for ansible is now available for Ansible Engine 27Red Hat Product Security has rated this update as having a security impactof Important A Common Vulnerability Scoring System (CVSS) ...
A flaw was found in Ansible Engine, all versions 27x, 28x and 29x prior to 2717, 289 and 296 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean An attacker could take advantage of this by altering the ansible_facts, such as an ...

Github Repositories

Poetry plugin for checking vulnerabilities in dependencies 🚀

Poetry Audit Plugin Poetry plugin for checking security vulnerabilities in dependencies based on safety $ poetry audit Scanning 19 packages • ansible-runner installed 112 affected <131 CVE PVE-2021-36995 • ansible-tower-cli installed 318 affected <320 CVE CVE-2020-1733 • jinja2 installed 20 affected &am