Information disclosure in Ansible - CVE-2020-1739
Published: July 7, 2020
Vulnerability identifier: #VU29564
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1739
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to password being exposed to local users when a password is set with the argument "password" of svn module. A local user can read the cmdline file from that particular PID on the procfs and obtain the password.
Affected software
Ansible
Red Hat Ansible Engine
ansible (Debian package)
ansible (Alpine package)
ansible-help
ansible
ansible (Red Hat package)
Fedora
openEuler
Red Hat Ansible Engine
ansible (Debian package)
ansible (Alpine package)
ansible-help
ansible
ansible (Red Hat package)
Fedora
openEuler
How to mitigate CVE-2020-1739
Install updates from vendor's website.
Ansible - addressed in versions 2.7.17, 2.8.8, 2.9.5, 2.7.17-1.el7ae, 2.8.11-1.el7ae, 2.8.11-1.el8ae, 2.9.7-1.el7ae, 2.9.7-1.el8ae
ansible (Debian package) - update to 2.7.7+dfsg-1+deb10u1
ansible (Alpine package) - update to 2.7.17-r0
ansible-help - addressed in versions 2.5.5-2, 2.5.5-6
ansible - addressed in versions 2.5.5-2, 2.5.5-6
ansible - addressed in versions 2.9.6-1.el7, 2.9.6-1.el8, 2.9.6-1.fc30, 2.9.6-1.fc31, 2.9.6-1.fc32, 2.9.7-1.el8
ansible (Red Hat package) - addressed in versions 2.9.7-1.el7ae, 2.9.7-1.el8ae
ansible (Debian package) - update to 2.7.7+dfsg-1+deb10u1
ansible (Alpine package) - update to 2.7.17-r0
ansible-help - addressed in versions 2.5.5-2, 2.5.5-6
ansible - addressed in versions 2.5.5-2, 2.5.5-6
ansible - addressed in versions 2.9.6-1.el7, 2.9.6-1.el8, 2.9.6-1.fc30, 2.9.6-1.fc31, 2.9.6-1.fc32, 2.9.7-1.el8
ansible (Red Hat package) - addressed in versions 2.9.7-1.el7ae, 2.9.7-1.el8ae
External References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1739
- https://github.com/ansible/ansible/issues/67797
- https://lists.debian.org/debian-lts-announce/2020/05/msg00005.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FWDK3QUVBULS3Q3PQTGEKUQYPSNOU5M3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QT27K5ZRGDPCH7GT3DRI3LO4IVDVQUB7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U3IMV3XEIUXL6S4KPLYYM4TVJQ2VNEP2/
Related Security Bulletins
- Information disclosure in Red Hat Ansible
- Information disclosure in ansible (Alpine package)
- Debian update for ansible
- Ansible Engine 2 update for ansible
- Ansible Engine 2 update for ansible
- Ansible Engine 2 update for ansible
- openEuler 20.03 LTS SP2 update for ansible
- openEuler 20.03 LTS SP1 update for ansible
- Red Hat update for Ansible engine
- Fedora 32 update for ansible
- Fedora 31 update for ansible
- Fedora 30 update for ansible
- Fedora EPEL 8 update for ansible
- Fedora EPEL 7 update for ansible
- Fedora EPEL 8 update for ansible