PT-2020-6574 · Red Hat+2 · Ansible Engine+3

Bcoca

·

Published

2020-05-11

·

Updated

2026-06-03

·

CVE-2020-10685

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ansible Engine versions 2.7.x through 2.7.17 Ansible Engine versions 2.8.x through 2.8.11 Ansible Engine versions 2.9.x through 2.9.7 Ansible Tower versions 3.4.5 and earlier Ansible Tower versions 3.5.5 and earlier Ansible Tower versions 3.6.3 and earlier
Description A flaw was found in Ansible Engine affecting the use of modules that decrypt vault files, such as assemble, script, unarchive, win copy, aws s3, or copy modules. The temporary directory created in /tmp leaves sensitive data unencrypted. On operating systems where /tmp is not a tmpfs but part of the root partition, the directory is only cleared on boot, and the decrypted data remains when the host is switched off. This leaves the system vulnerable when it is not running. Decrypted data must be cleared as soon as possible.
Recommendations For Ansible Engine versions 2.7.x through 2.7.17, update to version 2.7.17 or later. For Ansible Engine versions 2.8.x through 2.8.11, update to version 2.8.11 or later. For Ansible Engine versions 2.9.x through 2.9.7, update to version 2.9.7 or later. For Ansible Tower versions 3.4.5 and earlier, update to a version later than 3.4.5. For Ansible Tower versions 3.5.5 and earlier, update to a version later than 3.5.5. For Ansible Tower versions 3.6.3 and earlier, update to a version later than 3.6.3. As a temporary workaround, consider clearing the temporary directory in /tmp as soon as possible to minimize the risk of exploitation. Restrict access to the vulnerable modules, such as assemble, script, unarchive, win copy, aws s3, or copy, until the issue is resolved.

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2050
ALT-PU-2020-2069
BDU:2022-00274
CVE-2020-10685
DSA-4950-1
GHSA-77G3-3J5W-64W4
OESA-2025-2065
OPENSUSE-SU-2022:0081-1
OPENSUSE-SU-2024:10615-1
OPENSUSE-SU-2024:14244-1
OPENSUSE-SU-2024:14536-1
OPENSUSE-SU-2025:15605-1
OPENSUSE-SU-2025:15753-1
OPENSUSE-SU-2026:10944-1
PYSEC-2020-1
RHSA-2020:1541
RHSA-2020:1542
RHSA-2020:1543
RHSA-2020:1544
SUSE-SU-2020:3309-1

Affected Products

Alt Linux
Ansible Engine
Ansible Tower
Astra Linux