CVE-2020-1738

unknown
Published 2022-02-09 · Modified 2023-11-08
CVSS v3
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L
CVSS v2
VIR risk

Description

A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2020-1738.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-1738

OS impact

OSVersionStatusFixed in
debian debianbookwormaffected
debian debianbullseyeaffected
debian debianforkyaffected
debian debiansidaffected
debian debiantrixieaffected
suse slesaffected

Package impact

EcosystemPackageVulnerableFixed
python PyPIansible<=2.7.16
python PyPIansible>=2.8.0a1,<=2.8.10
python PyPIansible>=2.9.0a1,<=2.9.6
python PyPIansible>=2.9.0,<2.9.62.7.17

References

Verify integrity in audit chain (admin only). AS-IS.