PT-2020-6578 · Red Hat+2 · Ansible Engine+2

Published

2020-09-05

·

Updated

2024-05-06

·

CVE-2020-14365

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ansible Engine versions 2.8.x through 2.8.14 Ansible Engine versions 2.9.x through 2.9.12
Description A flaw was found in the Ansible Engine when installing packages using the dnf module. GPG signatures are ignored during installation even when disable gpg check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.
Recommendations For Ansible Engine versions 2.8.x through 2.8.14, update to version 2.8.15 or later. For Ansible Engine versions 2.9.x through 2.9.12, update to version 2.9.13 or later. As a temporary workaround, consider disabling the dnf module until a patch is available. Restrict access to the dnf module to minimize the risk of exploitation. Avoid using the force: true option when using the dnf module, as it may allow the installation of unverified packages.

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2923
ALT-PU-2020-3006
ALT-PU-2020-3025
ALT-PU-2020-3053
ALT-PU-2021-1800
BDU:2022-00281
CVE-2020-14365
DSA-4950-1
GHSA-M429-FHMV-C6Q2
MGASA-2020-0363
PYSEC-2020-209
RHSA-2020:3600
RHSA-2020:3601
RHSA-2020:3602
SUSE-SU-2020:3309-1
SUSE-SU-2024:1427-1
SUSE-SU-2024:1509-1

Affected Products

Alt Linux
Ansible Engine
Astra Linux