CVE-2020-10744

unknown
Published 2022-02-09 · Modified 2023-11-08
CVSS v3
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
CVSS v2
VIR risk

Description

An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2020-10744.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-10744

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.9.13+dfsg-1
debian debianbullseyefixed2.9.13+dfsg-1
debian debiansidfixed2.9.13+dfsg-1
debian debiantrixiefixed2.9.13+dfsg-1
debian debianforkyfixed2.9.13+dfsg-1
suse slesaffected

Package impact

EcosystemPackageVulnerableFixed
python PyPIansible>=2.10.0a1,<2.10.0rc12.10.0rc1
python PyPIansible<2.9.122.9.12
python PyPIansible>=2.9.0,<2.9.102.8.0a1

References

Verify integrity in audit chain (admin only). AS-IS.