CVE-2020-1739: Debian Linux

Low severity, CVSS 3.9. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

Affected products

  • Debian Debian Linux: version 8.0 only; version 10.0 only
  • Fedoraproject Fedora: version 30 only; version 31 only; version 32 only
  • Red Hat Ansible: up to and including 2.7.16; from 2.8.0, up to and including 2.8.8; from 2.9.0, up to and including 2.9.5
  • Red Hat Ansible Tower: up to and including 3.3.4; from 3.4.0, up to and including 3.4.5; from 3.5.0, up to and including 3.5.5; from 3.6.0, up to and including 3.6.3
  • Red Hat Cloudforms Management Engine: version 5.0 only
  • Red Hat Openstack: version 13 only

Published 2020-03-12. Last modified 2026-06-17.