CVE Published: 16/03/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: redhat |
Vendor: Red Hat |
Product: ansible Status : PUBLISHED
CVE-2020-1738 Description
A flaw was found in Ansible Engine when the module package or service is used and the parameter \'use\' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
Metrics
CVSS Version: 3.1 |
Base Score: 3.9 LOW Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L
l➤ Exploitability Metrics: Attack Vector (AV)* LOCAL Attack Complexity (AC)* HIGH Privileges Required (PR)* LOW User Interaction (UI)* REQUIRED Scope (S)* CHANGED