First published: Wed Feb 12 2020(Updated: )
A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Ansible | <2.7.17 | |
Redhat Ansible | >=2.8.0<2.8.11 | |
Redhat Ansible | >=2.9.0<2.9.7 | |
Redhat Ansible Tower | <=3.3.4 | |
Redhat Ansible Tower | >=3.3.5<=3.4.5 | |
Redhat Ansible Tower | >=3.5.0<=3.5.5 | |
Redhat Ansible Tower | >=3.6.0<=3.6.3 | |
Redhat Cloudforms Management Engine | =5.0 | |
Redhat Openstack | =13 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
debian/ansible | 2.7.7+dfsg-1+deb10u1 2.7.7+dfsg-1+deb10u2 2.10.7+merged+base+2.10.8+dfsg-1 7.3.0+dfsg-1 7.7.0+dfsg-3 | |
redhat/ansible-engine | <2.7.17 | 2.7.17 |
redhat/ansible-engine | <2.8.11 | 2.8.11 |
redhat/ansible-engine | <2.9.7 | 2.9.7 |
pip/ansible | >=2.9.0a1<2.9.8 | 2.9.8 |
pip/ansible | >=2.8.0a1<2.8.12 | 2.8.12 |
pip/ansible | >=2.7.0a1<2.7.18 | 2.7.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1735 is a vulnerability found in the Ansible Engine when the fetch module is used, allowing an attacker to intercept the module and inject a new path.
All versions in the 2.7.x, 2.8.x, and 2.9.x branches of Ansible Engine are believed to be vulnerable.
CVE-2020-1735 has a severity level of medium.
To fix CVE-2020-1735, you should update Ansible Engine to versions 2.7.17, 2.8.11, or 2.9.7, depending on the branch you are using.
You can find more information about CVE-2020-1735 on Red Hat's security page: https://access.redhat.com/security/cve/CVE-2020-1735.