Candidate: CVE-2020-1735 PublicDate: 2020-03-16 16:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1735 https://bugzilla.redhat.com/show_bug.cgi?id=1802085 Description: A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N [4.6 MEDIUM] Patches_ansible: upstream_ansible: needs-triage precise/esm_ansible: DNE trusty_ansible: ignored (out of standard support) trusty/esm_ansible: needs-triage xenial_ansible: ignored (end of standard support, was needs-triage) bionic_ansible: needs-triage eoan_ansible: ignored (reached end-of-life) focal_ansible: needs-triage groovy_ansible: not-affected (2.9.7+dfsg-1) hirsute_ansible: not-affected (2.9.7+dfsg-1) impish_ansible: not-affected (2.9.7+dfsg-1) jammy_ansible: not-affected (2.9.7+dfsg-1) devel_ansible: not-affected (2.9.7+dfsg-1)