CVE-2020-14365 describes a critical flaw in Ansible Engine versions 2.8.x before 2.8.15 and 2.9.x before 2.9.13, specifically impacting the dnf module's package installation process. This vulnerability allows the installation of malicious packages with ignored GPG signatures, even when signature checks are enabled by default, affecting various Debian and Red Hat Ansible-related products. With a CVSS score of 7.1 (HIGH), the flaw presents a significant risk to system integrity and availability through local, low-complexity attacks that can lead to arbitrary code execution. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.8.0, <= 2.8.15CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:* | ||
>= 2.9.0, <= 2.9.13CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:* | ||
>= 3.6.0, <= 3.6.5CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:* | ||
>= 3.7.0, <= 3.7.2CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_tower:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.