CVE-2020-1734: Red Hat Ansible Engine
High severity, CVSS 7.4. EPSS: 0.5% chance of exploitation in the next 30 days.
A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could take advantage and run arbitrary commands by overwriting the ansible facts.
Affected products
- Red Hat Ansible Engine: up to and including 2.7.16; version 2.8.8 only; version 2.9.5 only
- Red Hat Ansible Tower: up to and including 3.3.4; version 3.4.5 only; version 3.5.5 only; version 3.6.3 only
Published 2020-03-03. Last modified 2026-06-17.