Incorrect permission assignment for critical resource in Red Hat Ansible Engine - CVE-2020-1736
Published: June 15, 2020
Vulnerability identifier: #VU29025
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1736
CWE-ID: CWE-732
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists when a file is moved using "atomic_move" primitive as the file mode cannot be specified. A local user can gain unauthorized access to sensitive information on the system.
Affected software
Red Hat Ansible Engine
Gentoo Linux
Fedora
openEuler
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Data Computing Appliance (DCA)
ansible
ansible-help
Gentoo Linux
Fedora
openEuler
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Data Computing Appliance (DCA)
ansible
ansible-help
How to mitigate CVE-2020-1736
Install updates from vendor's website.
Red Hat Ansible Engine - addressed in versions 2.7.17, 2.8.11, 2.9.7
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0
ansible - update to 2.5.5-2
ansible-help - update to 2.5.5-2
ansible - addressed in versions 2.9.7-1.el7, 2.9.7-1.el8, 2.9.12-1.fc31, 2.9.12-1.fc32, 2.9.13-1.fc32
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0
ansible - update to 2.5.5-2
ansible-help - update to 2.5.5-2
ansible - addressed in versions 2.9.7-1.el7, 2.9.7-1.el8, 2.9.12-1.fc31, 2.9.12-1.fc32, 2.9.13-1.fc32
External References
Related Security Bulletins
- Multiple vulnerabilities in Red Hat Ansible Engine
- Gentoo update for Ansible
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- openEuler 20.03 LTS SP2 update for ansible
- Fedora EPEL 8 update for ansible
- Fedora EPEL 7 update for ansible
- Fedora 31 update for ansible
- Fedora 32 update for ansible
- Fedora 32 update for ansible