PT-2020-6578 · Red Hat+2 · Ansible Engine+2
Published
2020-09-05
·
Updated
2024-05-06
·
CVE-2020-14365
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ansible Engine versions 2.8.x through 2.8.14
Ansible Engine versions 2.9.x through 2.9.12
Description
A flaw was found in the Ansible Engine when installing packages using the dnf module. GPG signatures are ignored during installation even when
disable gpg check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.Recommendations
For Ansible Engine versions 2.8.x through 2.8.14, update to version 2.8.15 or later.
For Ansible Engine versions 2.9.x through 2.9.12, update to version 2.9.13 or later.
As a temporary workaround, consider disabling the dnf module until a patch is available.
Restrict access to the dnf module to minimize the risk of exploitation.
Avoid using the
force: true option when using the dnf module, as it may allow the installation of unverified packages.Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Ansible Engine
Astra Linux