CVE-2020-1739

NameCVE-2020-1739
DescriptionA flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-2202-1
NVD severitylow

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ansible (PTS)stretch (security), stretch2.2.1.0-2+deb9u1vulnerable
buster2.7.7+dfsg-1vulnerable
bullseye, sid2.9.13+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ansiblesourcejessie1.7.2+dfsg-2+deb8u3DLA-2202-1
ansiblesource(unstable)2.9.7+dfsg-1

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=1802178
https://github.com/ansible/ansible/issues/67797
https://github.com/ansible/ansible/pull/67829
https://github.com/ansible/ansible/commit/d91658ec0c8434c82c3ef98bfe9eb4e1027a43a3

Search for package or bug name: Reporting problems