SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-1738

If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file.

LOW 3.9EPSS 0.38%

Does this matter?

Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

CVSS 3.1
3.9 LOWCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L
EPSS
0.38% probability · 32th percentile
CISA KEV
Not listed
Weakness
CWE-88
Affected
redhat/ansible · redhat/ansible tower · redhat/cloudforms management engine · redhat/openstack
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.