Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-25636


A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are written directly to the root bucket, making possible to have collisions when running multiple ansible processes. This issue affects mainly the service availability.


Published

2020-10-05T13:15:13.490

Last Modified

2024-11-21T05:18:18.007

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.6 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:N/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

4.9

Weaknesses
  • Type: Secondary
    CWE-377
    CWE-552
  • Type: Primary
    CWE-552

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redhat ansible 2.10.1 Yes

References