CVE-2020-1735

Description

A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

Risk Information

Base Score
4.6
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.155

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2020-1735,CVE-2020-1753 are fixed in Python-ansible 2.7.18Windows
Vulnerabilities CVE-2020-1735,CVE-2020-1753 are fixed in Python-ansible 2.8.12Windows
Vulnerabilities CVE-2020-1735 are fixed in Python-ansible 2.9.8Windows
ansible security update(DSA-4950-1) ansible_2.7.7+dfsg-1+deb10u1_all.debLinux
ansible security update(DSA-4950-1) Debian_ansible_2.7.7+dfsg-1+deb10u1_all.debLinux
Vulnerabilities CVE-2020-1735,CVE-2020-1753 are fixed in Python-ansible for linux 2.7.18Linux
Vulnerabilities CVE-2020-1735,CVE-2020-1753 are fixed in Python-ansible for linux 2.8.12Linux
Vulnerabilities CVE-2020-1735 are fixed in Python-ansible for linux 2.9.8Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234