CVE-2020-1739
Summary
| CVE | CVE-2020-1739 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-12 18:15:00 UTC |
| Updated | 2023-11-07 03:19:00 UTC |
| Description | A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 2202-1] ansible security update |
MLIST |
lists.debian.org |
Third Party Advisory |
| [SECURITY] Fedora 31 Update: ansible-2.9.6-1.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| 1802178 – (CVE-2020-1739) CVE-2020-1739 ansible: svn module leaks password when specified as a parameter |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| [SECURITY] Fedora 30 Update: ansible-2.9.6-1.fc30 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Release Notes, Third Party Advisory |
| [SECURITY] Fedora 30 Update: ansible-2.9.6-1.fc30 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Debian -- Security Information -- DSA-4950-1 ansible |
DEBIAN |
www.debian.org |
|
| [SECURITY] Fedora 32 Update: ansible-2.9.6-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Release Notes, Third Party Advisory |
| Command used in subversion module is problematic · Issue #67797 · ansible/ansible · GitHub |
MISC |
github.com |
Issue Tracking, Third Party Advisory |
| [SECURITY] Fedora 32 Update: ansible-2.9.6-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 31 Update: ansible-2.9.6-1.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Release Notes, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178744 Debian Security Update for ansible (DSA 4950-1)
- 500010 Alpine Linux Security Update for ansible
- 501350 Alpine Linux Security Update for ansible-base
- 981357 Python (pip) Security Update for ansible (GHSA-923p-fr2c-g5m2)