PT-2020-14921 · Ansible+2 · Ansible Engine+3
Samdoran
·
Published
2020-03-16
·
Updated
2026-06-03
·
CVE-2020-1736
CVSS v4.0
4.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Ansible Engine versions 2.7.x through 2.9.x
Description
A flaw was found in Ansible Engine when a file is moved using the atomic move primitive, as the file mode cannot be specified. This sets the destination file's world-readable if the destination file does not exist, and if the file exists, the file could be changed to have less restrictive permissions before the move. This could lead to the disclosure of sensitive data.
Recommendations
For versions 2.7.x, 2.8.x, and 2.9.x, consider restricting file permissions to minimize the risk of sensitive data disclosure until a patch is available.
As a temporary workaround, consider implementing additional access controls to sensitive files to prevent unauthorized access.
Exploit
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Ansible-Core
Ansible Engine
Debian