CVE-2020-14365
Last modified
CVE-2020-14365 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Ansible Engine | >= 2.8.0, <= 2.8.15 |
| Redhat | Ansible Engine | >= 2.9.0, <= 2.9.13 |
| Redhat | Ansible Tower | >= 3.6.0, <= 3.6.5 |
| Redhat | Ansible Tower | >= 3.7.0, <= 3.7.2 |
| Redhat | Ansible Tower | 3.0 |
| Redhat | Ceph Storage | 2.0 |
| Redhat | Ceph Storage | 3.0 |
| Redhat | Openstack Platform | 10.0 |
| Redhat | Openstack Platform | 13.0 |
| Debian | Debian Linux | 10.0 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1869154Issue Tracking, Vendor Advisory
- https://www.debian.org/security/2021/dsa-4950Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1869154Issue Tracking, Vendor Advisory
- https://www.debian.org/security/2021/dsa-4950Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-14365?
How severe is CVE-2020-14365?
How do I fix CVE-2020-14365?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-1436A remote code execution vulnerability exists when the Window…8.8
- CVE-2020-14360A flaw was found in the X.Org Server before version 1.20.10.…7.8
- CVE-2020-14361A flaw was found in X.Org Server before xorg-x11-server 1.20…7.8
- CVE-2020-14362A flaw was found in X.Org Server before xorg-x11-server 1.20…7.8
- CVE-2020-14363An integer overflow vulnerability leading to a double-free w…7.8
- CVE-2020-14364An out-of-bounds read/write access flaw was found in the USB…5
- CVE-2020-14366A vulnerability was found in keycloak, where path traversal …7.5
- CVE-2020-14367A flaw was found in chrony versions before 3.5.1 when creati…6
- CVE-2020-14368A flaw was found in Eclipse Che in versions prior to 7.14.0 …7.1
- CVE-2020-14369This release fixes a Cross Site Request Forgery vulnerabilit…6.3
- CVE-2020-1437An elevation of privilege vulnerability exists in the way th…7.8
- CVE-2020-14370An information disclosure vulnerability was found in contain…5.3
Are you affected by CVE-2020-14365?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
