7.1

CVE-2020-14365

A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RedhatAnsible Engine Version >= 2.8.0 <= 2.8.15
RedhatAnsible Engine Version >= 2.9.0 <= 2.9.13
RedhatAnsible Tower Version >= 3.6.0 <= 3.6.5
RedhatAnsible Tower Version >= 3.7.0 <= 3.7.2
RedhatAnsible Tower Version3.0
RedhatCeph Storage Version2.0
RedhatCeph Storage Version3.0
RedhatOpenstack Platform Version10.0
RedhatOpenstack Platform Version13.0
DebianDebian Linux Version10.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.07% 0.222
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvd@nist.gov 6.6 3.9 9.2
AV:L/AC:L/Au:N/C:N/I:C/A:C
CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.