CVE-2020-1735
Description
A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
Risk Information
Base Score
4.6
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.155
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2020-1735,CVE-2020-1753 are fixed in Python-ansible 2.7.18 | Windows |
| Vulnerabilities CVE-2020-1735,CVE-2020-1753 are fixed in Python-ansible 2.8.12 | Windows |
| Vulnerabilities CVE-2020-1735 are fixed in Python-ansible 2.9.8 | Windows |
| ansible security update(DSA-4950-1) ansible_2.7.7+dfsg-1+deb10u1_all.deb | Linux |
| ansible security update(DSA-4950-1) Debian_ansible_2.7.7+dfsg-1+deb10u1_all.deb | Linux |
| Vulnerabilities CVE-2020-1735,CVE-2020-1753 are fixed in Python-ansible for linux 2.7.18 | Linux |
| Vulnerabilities CVE-2020-1735,CVE-2020-1753 are fixed in Python-ansible for linux 2.8.12 | Linux |
| Vulnerabilities CVE-2020-1735 are fixed in Python-ansible for linux 2.9.8 | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234