Vulnerabilities > CVE-2020-1734 - Unspecified vulnerability in Redhat Ansible Engine and Ansible Tower

047910
CVSS 7.4 - HIGH
Attack vector
LOCAL
Attack complexity
HIGH
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
LOW
local
high complexity
redhat

Summary

A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could take advantage and run arbitrary commands by overwriting the ansible facts.

Vulnerable Configurations

Part Description Count
Application
Redhat
294