CVE-2020-1735: Debian Linux

Medium severity, CVSS 4.6. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 30 only; version 31 only; version 32 only
  • Red Hat Ansible: before 2.7.17 (fixed in 2.7.17); from 2.8.0, before 2.8.11 (fixed in 2.8.11); from 2.9.0, before 2.9.7 (fixed in 2.9.7)
  • Red Hat Ansible Tower: up to and including 3.3.4; from 3.3.5, up to and including 3.4.5; from 3.5.0, up to and including 3.5.5; from 3.6.0, up to and including 3.6.3
  • Red Hat Cloudforms Management Engine: version 5.0 only
  • Red Hat Openstack: version 13 only

Published 2020-03-16. Last modified 2026-06-17.