CVE-2020-10684: Debian Linux
High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.
Affected products
- Debian Debian Linux: version 10.0 only
- Fedoraproject Fedora: version 30 only; version 31 only; version 32 only
- Red Hat Ansible: from 2.7.0, before 2.7.17 (fixed in 2.7.17); from 2.8.0, before 2.8.9 (fixed in 2.8.9); from 2.9.0, before 2.9.6 (fixed in 2.9.6)
- Red Hat Ansible Tower: up to and including 3.3.5; from 3.5.0, up to and including 3.5.5; from 3.6.0, up to and including 3.6.3
- Red Hat Openstack: version 10 only; version 13 only
Published 2020-03-24. Last modified 2026-06-17.