CVE-2020-25635

NameCVE-2020-25635
DescriptionA flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed. Files would remain in the bucket exposing the data. This issue affects directly data confidentiality.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitylow

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ansible (PTS)stretch2.2.1.0-2+deb9u1fixed
stretch (security)2.2.1.0-2+deb9u2fixed
buster2.7.7+dfsg-1fixed
buster (security)2.7.7+dfsg-1+deb10u1fixed
bookworm, sid, bullseye2.10.7+merged+base+2.10.8+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ansiblesource(unstable)(not affected)

Notes

- ansible <not-affected> (Vulnerable connection/aws_ssm plugin not included)
https://github.com/ansible-collections/community.aws/issues/222

Search for package or bug name: Reporting problems