Code Injection in Red Hat Ansible Engine - CVE-2020-10684
Published: June 15, 2020
Vulnerability details
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation when using "ansible_facts" as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the "ansible_facts" after the clean. A local user can alter the "ansible_facts", such as "ansible_hosts", "users" and any other key data which would lead into privilege escalation or code injection
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
Fedora
openEuler
ansible (Debian package)
ansible
ansible-help
ansible (Red Hat package)
Ansible
How to mitigate CVE-2020-10684
ansible (Debian package) - update to 2.7.7+dfsg-1+deb10u1
ansible - addressed in versions 2.5.5-2, 2.5.5-6
ansible-help - addressed in versions 2.5.5-2, 2.5.5-6
Ansible - addressed in versions 2.7.17-1.el7ae, 2.8.11-1.el7ae, 2.8.11-1.el8ae, 2.9.7-1.el7ae, 2.9.7-1.el8ae
ansible - addressed in versions 2.9.7-1.el7, 2.9.7-1.el8, 2.9.7-1.fc30, 2.9.7-1.fc31, 2.9.7-1.fc32
ansible (Red Hat package) - addressed in versions 2.9.7-1.el7ae, 2.9.7-1.el8ae
External References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10684
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DKPA4KC3OJSUFASUYMG66HKJE7ADNGFW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MRRYUU5ZBLPBXCYG6CFP35D64NP2UB2S/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WQVOQD4VAIXXTVQAJKTN7NUGTJFE2PCB/
- https://security.gentoo.org/glsa/202006-11
Related Security Bulletins
- Multiple vulnerabilities in Red Hat Ansible Engine
- Gentoo update for Ansible
- Debian update for ansible
- Ansible Engine 2 update for ansible
- Ansible Engine 2 update for ansible
- Ansible Engine 2 update for ansible
- openEuler 20.03 LTS SP2 update for ansible
- openEuler 20.03 LTS SP1 update for ansible
- Red Hat update for Ansible engine
- Fedora 32 update for ansible
- Fedora 30 update for ansible
- Fedora 31 update for ansible
- Fedora EPEL 8 update for ansible
- Fedora EPEL 7 update for ansible