CVE-2020-1738: Low severity redhat ansible vulnerability
A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-1738?
CVE-2020-1738 is a vulnerability in Ansible Engine when the module package or service is used without specifying the 'use' parameter.
What is the severity of CVE-2020-1738?
The severity of CVE-2020-1738 is rated as low, with a severity value of 3.9.
Which versions of Ansible are affected by CVE-2020-1738?
Versions 2.7.x, 2.8.x, and 2.9.x branches of Ansible are affected by CVE-2020-1738.
How can I fix CVE-2020-1738?
To fix CVE-2020-1738, it is recommended to specify the 'use' parameter when using the module package or service in Ansible.
Where can I find more information about CVE-2020-1738?
More information about CVE-2020-1738 can be found at the following references: [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1738), [GitHub](https://github.com/ansible/ansible/issues/67796), [Gentoo Security](https://security.gentoo.org/glsa/202006-11).