Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Abeluck

#21248of 53,630
11.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2020-16142
5.0
2020-10-05
Ansible · Ansible Base · CVE-2020-25635
**Name of the Vulnerable Software and Affected Versions** Ansible Base (affected versions not specified) **Description** A flaw was found in Ansible Base when using the `aws ssm` connection plugin. The issue arises because the garbage collector does not run after a playbook run is completed, resulting in files remaining in the bucket and exposing data. This directly affects data confidentiality. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2020-16143
6.6
2020-10-05
Ansible · Ansible Base · CVE-2020-25636
**Name of the Vulnerable Software and Affected Versions** Ansible Base (affected versions not specified) **Description** A flaw was found in Ansible Base when using the `aws ssm` connection plugin, as there is no namespace separation for file transfers. Files are written directly to the root bucket, making it possible to have collisions when running multiple Ansible processes. This issue affects mainly the service availability. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.