Improper Verification of Cryptographic Signature in Ansible - CVE-2020-14365
Published: September 23, 2020 / Updated: October 2, 2020
Vulnerability details
The vulnerability allows a local authenticated user to #BASIC_IMPACT#.
A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.
Affected software
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Manager Proxy Module
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Manager Client Tools for SLE Micro
SUSE Manager Client Tools Beta for SLE Micro
SUSE Linux Enterprise Server for SAP Applications
SUSE Manager Client Tools Beta for SLE
SUSE Manager Client Tools for SLE
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Package Hub 15
openSUSE Leap
ansible (Debian package)
ansible (Alpine package)
ansible-base (Alpine package)
mgrctl
mgrctl-bash-completion
mgrctl-zsh-completion
POS_Image-Graphical7
POS_Image-JeOS7
dracut-saltboot
golang-github-prometheus-promu
golang-github-prometheus-node_exporter
ansible (Red Hat package)
ansible-doc
ansible-test
ansible
python3-spacewalk-koan
spacewalk-koan
mgr-daemon
python3-uyuni-common-libs
uyuni-proxy-systemd-services
spacewalk-client-tools
spacewalk-check
python3-spacewalk-client-tools
python3-spacewalk-check
spacewalk-client-setup
python3-spacewalk-client-setup
spacecmd
supportutils-plugin-susemanager-client
grafana
grafana-debuginfo
Data Computing Appliance (DCA)
Ansible Automation Platform
OpenShift Virtualization
How to mitigate CVE-2020-14365
ansible (Debian package) - update to 2.7.7+dfsg-1+deb10u1
ansible (Alpine package) - update to 2.9.13-r0
ansible-base (Alpine package) - update to 2.10.2-r0
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0
mgrctl - update to 0.1.7-159000.3.8.1
mgrctl-bash-completion - update to 0.1.7-159000.3.8.1
mgrctl-zsh-completion - update to 0.1.7-159000.3.8.1
POS_Image-Graphical7 - addressed in versions 0.1.1710765237.46af599-150000.1.21.2, 0.1.1710765237.46af599-159000.3.24.2
POS_Image-JeOS7 - addressed in versions 0.1.1710765237.46af599-150000.1.21.2, 0.1.1710765237.46af599-159000.3.24.2
dracut-saltboot - addressed in versions 0.1.1710765237.46af599-150000.1.53.2, 0.1.1710765237.46af599-159000.3.33.2
golang-github-prometheus-promu - update to 0.14.0-150000.3.18.2
Ansible Automation Platform - addressed in versions 1.0, 1.1
golang-github-prometheus-node_exporter - update to 1.5.0-159000.6.2.1
OpenShift Virtualization - update to 2.4.2
ansible (Red Hat package) - addressed in versions 2.9.13-1.el7ae, 2.9.13-1.el8ae
ansible-doc - addressed in versions 2.9.27-150000.1.17.2, 2.9.27-159000.3.12.2
ansible-test - update to 2.9.27-150000.1.17.2
ansible - addressed in versions 2.9.27-150000.1.17.2, 2.9.27-159000.3.12.2
python3-spacewalk-koan - update to 4.3.6-150000.3.33.2
spacewalk-koan - update to 4.3.6-150000.3.33.2
mgr-daemon - update to 4.3.9-150000.1.47.2
python3-uyuni-common-libs - update to 4.3.10-150000.1.39.2
uyuni-proxy-systemd-services - update to 4.3.12-150000.1.21.2
spacewalk-client-tools - addressed in versions 4.3.19-150000.3.89.2, 5.0.4-159000.6.54.2
spacewalk-check - addressed in versions 4.3.19-150000.3.89.2, 5.0.4-159000.6.54.2
python3-spacewalk-client-tools - addressed in versions 4.3.19-150000.3.89.2, 5.0.4-159000.6.54.2
python3-spacewalk-check - addressed in versions 4.3.19-150000.3.89.2, 5.0.4-159000.6.54.2
spacewalk-client-setup - addressed in versions 4.3.19-150000.3.89.2, 5.0.4-159000.6.54.2
python3-spacewalk-client-setup - addressed in versions 4.3.19-150000.3.89.2, 5.0.4-159000.6.54.2
spacecmd - addressed in versions 4.3.27-150000.3.116.2, 5.0.5-159000.6.48.2
supportutils-plugin-susemanager-client - update to 5.0.3-159000.6.21.2
grafana - addressed in versions 9.5.16-159000.4.30.2, 9.5.18-150000.1.63.2
grafana-debuginfo - addressed in versions 9.5.16-159000.4.30.2, 9.5.18-150000.1.63.2
External References
Related Security Bulletins
- Improper Verification of Cryptographic Signature in Ansible
- Improper Verification of Cryptographic Signature in ansible (Alpine package)
- Improper Verification of Cryptographic Signature in ansible-base (Alpine package)
- Debian update for ansible
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Ansible Engine 2 update for ansible
- Ansible Engine 2 update for ansible
- SUSE update for Security Beta update for SUSE Manager Client Tools and Salt
- SUSE update for SUSE Manager Client Tools
- Ansible Engine 2Red Hat Product Security has rated this update as having a security impactof Important update for ansible
- Multiple vulnerabilities in Ansible Automation Platform 1.0 packages
- Multiple vulnerabilities in Ansible Automation Platform 1.1 packages
- Multiple vulnerabilities in OpenShift Virtualization 2.4
- Multiple vulnerabilities in Ansible Automation Platform 1.0 packages
- Multiple vulnerabilities in Ansible Automation Platform 1.1 packages