PT-2020-5155 · Red Hat+2 · Ansible+2
Samdoran
·
Published
2019-09-03
·
Updated
2026-06-03
·
CVE-2020-1734
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L |
Name of the Vulnerable Software and Affected Versions
Ansible (affected versions not specified)
Description
The issue is related to the pipe lookup plugin of Ansible, where arbitrary commands can be run when the plugin uses
subprocess.Popen() with shell=True by overwriting Ansible facts. The variable is not escaped by the quote plugin, allowing an attacker to take advantage and run arbitrary commands by overwriting the Ansible facts. This could potentially allow a perpetrator to elevate their privileges and execute arbitrary code.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Ansible
Debian