VDB
CVE-2020-1738
CVE-2020-1738
PUBLISHED
CVSS 3.9000000953674316 LOW
A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
EPSS 0.40% · 31.7th percentile
Risk Scores
CVSS 3.1
3.9000000953674316
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L
EPSS Score
0.40%
31.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:14.04:LTS | ansible | 1.5.4+dfsg-1ubuntu0.1~esm1, *, * |
| Ubuntu:Pro:22.04:LTS | ansible | 2.10.7+merged+base+2.10.8+dfsg-1, *, 0 |
| Ubuntu:Pro:16.04:LTS | ansible | 1.9.2+dfsg-2, 2.0.0.2-2ubuntu1.1, 2.0.0.2-2ubuntu1.2 |
| Ubuntu:Pro:18.04:LTS | ansible | 2.5.1+dfsg-1ubuntu0.1+esm2, 0, 2.3.1.0+dfsg-2 |
| Ubuntu:25.10 | ansible | 0, 11.2.0+dfsg-1, 12.0.0~a2+dfsg-1 |
| Ubuntu:Pro:20.04:LTS | ansible | 2.9.4+dfsg-1, 2.9.6+dfsg-1, 2.9.2+dfsg-1 |
| Ubuntu:24.04:LTS | ansible | 0, 7.7.0+dfsg-1, 7.7.0+dfsg-3 |
Timeline
- Mar 16, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 4, 2021 CVE Updated
- Aug 25, 2021 EPSS Score
- Oct 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 2, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 4, 2022 EPSS Score
- Jul 6, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2020-1738 third-party-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1802164 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-1738 third-party-advisory