CVE Database
/

CVE-2020-1739

Back to search

CVE-2020-1739

Published: Mar 12, 2020

Modified: Aug 4, 2024

PUBLISHED

CVSS v3.1

3.9

LOW

Description

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

VendorProductVersions

Red Hat

Ansible

affected
2.7.16 and prior
affected
2.8.8 and prior
affected
2.9.5 and prior

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

Required

Scope

Unchanged

Confidentiality

Low

Integrity

Low

Availability

None

References

FEDORA-2020-a3f12bcff4
vendor-advisory
x_refsource_FEDORA
FEDORA-2020-0cab7041f7
vendor-advisory
x_refsource_FEDORA
FEDORA-2020-87f5e1e829
vendor-advisory
x_refsource_FEDORA
DSA-4950
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now