PT-2020-14921 · Ansible+2 · Ansible Engine+3

Samdoran

·

Published

2020-03-16

·

Updated

2026-06-03

·

CVE-2020-1736

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ansible Engine versions 2.7.x through 2.9.x
Description A flaw was found in Ansible Engine when a file is moved using the atomic move primitive, as the file mode cannot be specified. This sets the destination file's world-readable if the destination file does not exist, and if the file exists, the file could be changed to have less restrictive permissions before the move. This could lead to the disclosure of sensitive data.
Recommendations For versions 2.7.x, 2.8.x, and 2.9.x, consider restricting file permissions to minimize the risk of sensitive data disclosure until a patch is available. As a temporary workaround, consider implementing additional access controls to sensitive files to prevent unauthorized access.

Exploit

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2923
ALT-PU-2020-3006
ALT-PU-2021-1800
CVE-2020-1736
GHSA-X7JH-595Q-WQ82
OESA-2021-1349
OPENSUSE-SU-2022:0081-1
OPENSUSE-SU-2024:10615-1
OPENSUSE-SU-2024:14244-1
OPENSUSE-SU-2024:14536-1
OPENSUSE-SU-2025:15605-1
OPENSUSE-SU-2025:15753-1
OPENSUSE-SU-2026:10944-1
PYSEC-2020-8
RHSA-2020:3600
SUSE-SU-2020:3309-1

Affected Products

Alt Linux
Ansible-Core
Ansible Engine
Debian