ansible: path injection on dest parameter in fetch module
Published Mar 16, 2020
4.6
MEDIUMCVSS 4.0
EPSS 0.47%
Description
A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
Affected products
-
- Version 2.7.x, 2.8.x, 2.9.xStatusaffectedConstraints-
- Version
Configuration 1
- < 2.7.17
- ≥ 2.8.0 · < 2.8.11
- ≥ 2.9.0 · < 2.9.7
- ≤ 3.3.4
- ≥ 3.3.5 · ≤ 3.4.5
- ≥ 3.5.0 · ≤ 3.5.5
- ≥ 3.6.0 · ≤ 3.6.3
- 5.0
- 13
Configuration 2
- 10.0
Configuration 3
- 30
- 31
- 32
No data.
Red Hat Ansible Engine 2 for RHEL 7
ansible-0:2.9.7-1.el7ae
Fixed · RHSA-2020:1542
Red Hat Ansible Engine 2 for RHEL 8
ansible-0:2.9.7-1.el8ae
Fixed · RHSA-2020:1542
Red Hat Ansible Engine 2.7 for RHEL 7
ansible-0:2.7.17-1.el7ae
Fixed · RHSA-2020:1544
Red Hat Ansible Engine 2.8 for RHEL 7
ansible-0:2.8.11-1.el7ae
Fixed · RHSA-2020:1543
Red Hat Ansible Engine 2.8 for RHEL 8
ansible-0:2.8.11-1.el8ae
Fixed · RHSA-2020:1543
Red Hat Ansible Engine 2.9 for RHEL 7
ansible-0:2.9.7-1.el7ae
Fixed · RHSA-2020:1541
Red Hat Ansible Engine 2.9 for RHEL 8
ansible-0:2.9.7-1.el8ae
Fixed · RHSA-2020:1541
Red Hat Ansible Tower 3.4 for RHEL 7
ansible-tower-34/ansible-tower-memcached:1.4.15-28
Fixed · RHBA-2020:0547
Red Hat Ansible Tower 3.4 for RHEL 7
ansible-tower-35/ansible-tower-memcached:1.4.15-28
Fixed · RHBA-2020:0547
Red Hat Ansible Tower 3.4 for RHEL 7
ansible-tower-37/ansible-tower-memcached-rhel7:1.4.15-28
Fixed · RHBA-2020:0547
Red Hat Ansible Tower 3.5 for RHEL 7
ansible-tower-35/ansible-tower:3.5.6-1
Fixed · RHBA-2020:1539
CloudForms Management Engine 5
ansible-tower
Not affected
Red Hat Ceph Storage 2
ansible
Out of support scope
Red Hat Ceph Storage 3
ansible
Will not fix
Red Hat OpenStack Platform 10 (Newton)
ansible
Out of support scope
Red Hat OpenStack Platform 13 (Queens)
ansible
Will not fix
Red Hat Storage 3
ansible
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Engine 2 for RHEL 7 | ansible-0:2.9.7-1.el7ae | Fixed | RHSA-2020:1542 |
| Red Hat Ansible Engine 2 for RHEL 8 | ansible-0:2.9.7-1.el8ae | Fixed | RHSA-2020:1542 |
| Red Hat Ansible Engine 2.7 for RHEL 7 | ansible-0:2.7.17-1.el7ae | Fixed | RHSA-2020:1544 |
| Red Hat Ansible Engine 2.8 for RHEL 7 | ansible-0:2.8.11-1.el7ae | Fixed | RHSA-2020:1543 |
| Red Hat Ansible Engine 2.8 for RHEL 8 | ansible-0:2.8.11-1.el8ae | Fixed | RHSA-2020:1543 |
| Red Hat Ansible Engine 2.9 for RHEL 7 | ansible-0:2.9.7-1.el7ae | Fixed | RHSA-2020:1541 |
| Red Hat Ansible Engine 2.9 for RHEL 8 | ansible-0:2.9.7-1.el8ae | Fixed | RHSA-2020:1541 |
| Red Hat Ansible Tower 3.4 for RHEL 7 | ansible-tower-34/ansible-tower-memcached:1.4.15-28 | Fixed | RHBA-2020:0547 |
| Red Hat Ansible Tower 3.4 for RHEL 7 | ansible-tower-35/ansible-tower-memcached:1.4.15-28 | Fixed | RHBA-2020:0547 |
| Red Hat Ansible Tower 3.4 for RHEL 7 | ansible-tower-37/ansible-tower-memcached-rhel7:1.4.15-28 | Fixed | RHBA-2020:0547 |
| Red Hat Ansible Tower 3.5 for RHEL 7 | ansible-tower-35/ansible-tower:3.5.6-1 | Fixed | RHBA-2020:1539 |
| CloudForms Management Engine 5 | ansible-tower | Not affected | n/a |
| Red Hat Ceph Storage 2 | ansible | Out of support scope | n/a |
| Red Hat Ceph Storage 3 | ansible | Will not fix | n/a |
| Red Hat OpenStack Platform 10 (Newton) | ansible | Out of support scope | n/a |
| Red Hat OpenStack Platform 13 (Queens) | ansible | Will not fix | n/a |
| Red Hat Storage 3 | ansible | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Ansible Engine 2.7.16, 2.8.10, and 2.9.6 as well as previous versions are affected. Ansible Tower 3.4.5, 3.5.5 and 3.6.3 as well as previous versions are affected. In Red Hat OpenStack Platform, because the flaw has a lower impact, ansible is not directly customer exposed, and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP ansible package.
Red Hat mitigation
Currently, there is no mitigation for this issue except avoid using the affected fetch module when possible.
References (23)
- https://access.redhat.com/security/cve/CVE-2020-1735 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1802085 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1735 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://github.com/advisories/GHSA-gfr2-qpxh-qj9m Advisory
- https://github.com/ansible/ansible/blob/stable-2.9/changelogs/CHANGELOG-v2.9.rst#security-fixes-7
- https://github.com/ansible/ansible/commit/18f91bbb88a84b1d3614ef41c3550da735592ac1
- https://github.com/ansible/ansible/commit/40969ff43812fabf5397f818d9e521f9b39c9c9a
- https://github.com/ansible/ansible/commit/de9a4f5474c5f5db442ae7493d6b5da7177e335d
- https://github.com/ansible/ansible/issues/67793 x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory
- https://github.com/ansible/ansible/pull/69023
- https://github.com/ansible/ansible/pull/69024
- https://github.com/ansible/ansible/pull/69025
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2020-7.yaml
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DKPA4KC3OJSUFASUYMG66HKJE7ADNGFW/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRRYUU5ZBLPBXCYG6CFP35D64NP2UB2S/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WQVOQD4VAIXXTVQAJKTN7NUGTJFE2PCB/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DKPA4KC3OJSUFASUYMG66HKJE7ADNGFW
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MRRYUU5ZBLPBXCYG6CFP35D64NP2UB2S
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WQVOQD4VAIXXTVQAJKTN7NUGTJFE2PCB
- https://nvd.nist.gov/vuln/detail/CVE-2020-1735
- https://security.gentoo.org/glsa/202006-11 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-1735
- https://www.debian.org/security/2021/dsa-4950 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.