Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Required
Privileges Required
Low
Attack Vector
Local
0

CVE-2020-1738

Disclosure Date: March 16, 2020
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

A flaw was found in Ansible Engine when the module package or service is used and the parameter ‘use’ is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
3.9 Low
Impact Score:
2.7
Exploitability Score:
0.8
Vector:
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L
Attack Vector (AV):
Local
Attack Complexity (AC):
High
Privileges Required (PR):
Low
User Interaction (UI):
Required
Scope (S):
Changed
Confidentiality (C):
None
Integrity (I):
Low
Availability (A):
Low

General Information

Vendors

  • redhat

Products

  • ansible,
  • ansible tower,
  • cloudforms management engine 5.0,
  • openstack 13

Additional Info

Technical Analysis