CVE-2020-1734

Description

A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could take advantage and run arbitrary commands by overwriting the ansible facts.

Risk Information

Base Score
7.4
MODERATE
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L
EPSS Score
Exploitation Probability
0.131

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2020-10744,CVE-2020-1734 are fixed in Python-ansible 2.10.0rc1Windows
Vulnerabilities CVE-2020-1734 are fixed in Python-ansible 2.8.13Windows
Vulnerabilities CVE-2020-1734 are fixed in Python-ansible 2.9.11Windows
Vulnerabilities CVE-2020-10744,CVE-2020-1734 are fixed in Python-ansible for linux 2.10.0rc1Linux
Vulnerabilities CVE-2020-1734 are fixed in Python-ansible for linux 2.8.13Linux
Vulnerabilities CVE-2020-1734 are fixed in Python-ansible for linux 2.9.11Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234