ZeroHour

CVE-2020-1735

PoC
CVSS 3.1
4.6 medium
EPSS
<1%p41
Published
()
Modified
Description

A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

Vendors
redhatdebianfedoraproject
Products
ansible, ansible tower, cloudforms management engine, openstack, debian linux, fedora
Weakness
CWE-22
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.