CVE-2020-10729
Last modified
CVE-2020-10729 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as the template caching action for the same file since no re-evaluation happens. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as the template caching action for the same file since no re-evaluation happens. The highest threat from this vulnerability would be that all passwords are exposed at once for the file. This flaw affects Ansible Engine versions before 2.9.6.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Ansible Engine | < 2.9.6 |
| Debian | Debian Linux | 10.0 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1831089Issue Tracking, Vendor Advisory
- https://github.com/ansible/ansible/issues/34144Exploit, Issue Tracking, Third Party Advisory
- https://www.debian.org/security/2021/dsa-4950Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1831089Issue Tracking, Vendor Advisory
- https://github.com/ansible/ansible/issues/34144Exploit, Issue Tracking, Third Party Advisory
- https://www.debian.org/security/2021/dsa-4950Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-10729?
How severe is CVE-2020-10729?
How do I fix CVE-2020-10729?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-10723A memory corruption issue was found in DPDK versions 17.05 a…6.7
- CVE-2020-10724A vulnerability was found in DPDK versions 18.11 and above. …4.4
- CVE-2020-10725A flaw was found in DPDK version 19.11 and above that allows…7.7
- CVE-2020-10726A vulnerability was found in DPDK versions 19.11 and above. …4.4
- CVE-2020-10727A flaw was found in ActiveMQ Artemis management API from ver…5.5
- CVE-2020-10728A flaw was found in automationbroker/apb container in versio…7.8
- CVE-2020-1073A remote code execution vulnerability exists in the way that…8.1
- CVE-2020-10730A NULL pointer dereference, or possible use-after-free flaw …6.5
- CVE-2020-10731A flaw was found in the nova_libvirt container provided by t…9.9
- CVE-2020-10732A flaw was found in the Linux kernel's implementation of Use…4.4
- CVE-2020-10733The Windows installer for PostgreSQL 9.5 - 12 invokes system…7.3
- CVE-2020-10734A vulnerability was found in keycloak in the way that the OI…3.3
Are you affected by CVE-2020-10729?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
