CVE-2020-1736

unknown
Published 2022-02-09 · Modified 2023-11-08
CVSS v3
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v2
VIR risk

Description

A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be changed to have less restrictive permissions before the move. This could lead to the disclosure of sensitive data. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2020-1736.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-1736

OS impact

OSVersionStatusFixed in
debian debianforkyaffected
debian debianbookwormaffected
debian debianbullseyeaffected
debian debiansidaffected
debian debiantrixieaffected
suse slesaffected

Package impact

EcosystemPackageVulnerableFixed
python PyPIansible>=2.7.0,<=2.10.0
python PyPIansible>=2.9.0,<2.9.62.7.17

References

Verify integrity in audit chain (admin only). AS-IS.