Lucene search

K
redhatcveRedhat.comRH:CVE-2020-1739
HistoryFeb 18, 2020 - 2:30 p.m.

CVE-2020-1739

2020-02-1814:30:18
redhat.com
access.redhat.com
15

0.0005 Low

EPSS

Percentile

16.5%

A flaw was found in Ansible Engine. When a password is set with the argument “password” of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

Mitigation

Instead of using the parameter 'password' of the subversion module, provide the password with stdin.