CVE-2020-1734

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-1734
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-1734.json
Aliases
Published
2020-03-03T22:15:10Z
Modified
2023-11-29T08:09:23.193914Z
Details

A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could take advantage and run arbitrary commands by overwriting the ansible facts.

References

Affected packages

Git / github.com/ansible/ansible

Affected ranges

Type
GIT
Repo
https://github.com/ansible/ansible
Events
Introduced
0The exact introduced commit is unknown
Last affected
Last affected

Affected versions

0.*

0.0.1
0.0.2
0.01
0.3
0.7

stable-2.*

stable-2.9-branchpoint

v1.*

v1.0
v1.1
v1.2
v1.4.0
v1.5.0
v1.5.1
v1.6.0

Other

v1_last

v2.*

v2.0.0-0.1.alpha1
v2.0.0-0.2.alpha2
v2.0.0-0.3.beta1
v2.0.0-0.4.beta2
v2.0.0-0.5.beta3
v2.6.0a1
v2.7.0.a1
v2.8.0
v2.8.0a1
v2.8.0b1
v2.8.0rc1
v2.8.0rc2
v2.8.0rc3
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.5
v2.8.6
v2.8.7
v2.8.8
v2.9.0
v2.9.0b1
v2.9.0rc1
v2.9.0rc2
v2.9.0rc3
v2.9.0rc4
v2.9.0rc5
v2.9.1
v2.9.2
v2.9.3
v2.9.4
v2.9.5