Vulnerability CVE-2020-1739: Information

Description

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Published: March 12, 2020
Modified: Nov. 7, 2023
Error type identifier: CWE-200

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
ansiblep102.8.10-alt12.9.27-alt3.p10.2ALT-PU-2020-1453-1247669Fixed
ansiblep92.8.10-alt12.9.27-alt1ALT-PU-2020-1490-1247670Fixed
ansiblec10f12.8.10-alt12.9.27-alt3.p10.1ALT-PU-2020-1453-1247669Fixed
ansiblec9f22.8.10-alt12.9.26-alt2ALT-PU-2020-1490-1247670Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:*
      End including
      3.3.4

      cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:*
      Start including
      3.6.0
      End including
      3.6.3

      cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:*
      Start including
      3.5.0
      End including
      3.5.5

      cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:*
      Start including
      3.4.0
      End including
      3.4.5

      cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
      Start including
      2.9.0
      End including
      2.9.5

      cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
      End including
      2.7.16

      cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
      Start including
      2.8.0
      End including
      2.8.8

      Configuration 2

      cpe:2.3:a:redhat:cloudforms_management_engine:5.0:*:*:*:*:*:*:*

      cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*