CVE-2020-1739
Description
A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument password of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.
Risk Information
Base Score
3.9
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.045
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities are fixed in Python-ansible 2.7.17 | Windows |
| Multiple vulnerabilities are fixed in Python-ansible 2.8.11 | Windows |
| Multiple vulnerabilities are fixed in Python-ansible 2.9.7 | Windows |
| Multiple vulnerabilities are affected in Python-ansible 2.7.16 | Windows |
| Multiple vulnerabilities are affected in Python-ansible 2.8.10 | Windows |
| Multiple vulnerabilities are affected in Python-ansible 2.9.6 | Windows |
| ansible security update(DSA-4950-1) ansible_2.7.7+dfsg-1+deb10u1_all.deb | Linux |
| ansible security update(DSA-4950-1) Debian_ansible_2.7.7+dfsg-1+deb10u1_all.deb | Linux |
| Multiple vulnerabilities are fixed in Python-ansible for linux 2.7.17 | Linux |
| Multiple vulnerabilities are fixed in Python-ansible for linux 2.8.11 | Linux |
| Multiple vulnerabilities are fixed in Python-ansible for linux 2.9.7 | Linux |
| Multiple vulnerabilities are affected in Python-ansible for linux 2.7.16 | Linux |
| Multiple vulnerabilities are affected in Python-ansible for linux 2.8.10 | Linux |
| Multiple vulnerabilities are affected in Python-ansible for linux 2.9.6 | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234