GHSA-77g3-3j5w-64w4 · Severity: medium · Ecosystem: pip — Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible
A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when using modules which decrypts vault files such as assemble, script, unarchive, win_copy, aws_s3 or copy modules. The temporary directory is created in /tmp leaves the s ts unencrypted. On Operating Systems which /tmp is not a tmpfs but part of the root partition, the directory is only cleared on boot and the decryp emains when the host is switched off. The system will be vulnerable when the system is not running. So decrypted data must be cleared as soon as possible and the data which normally is encrypted ble.
Conclusion & alert: CVE-2020-10685 is rated Low Risk (33.7/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.17%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-01-05 | 0.13% | 0.17% | +0.05% |
| 2 | 2025-06-19 | 0.16% | 0.13% | -0.03% |
| 3 | 2025-03-30 | — | 0.16% | — |
Full EPSS history (13 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.0 | 3.1 | MEDIUM |
|
1.3 | 3.6 | [email protected] |
| 5.5 | 3.1 | MEDIUM |
|
1.8 | 3.6 | [email protected] |
| 1.9 | 2.0 | LOW |
|
3.4 | 2.9 | [email protected] |
GHSA-77g3-3j5w-64w4 · Severity: medium · Ecosystem: pip — Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2020-10685 not yet assigned priority: Debian including 1 source packages (ansible), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2020-10685 |
gentoo
|
normal | CVE-2020-10685: 1 GLSA(s) (202006-11), 1 atom(s) (app-admin/ansible); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2020-10685 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2020-10685 |
suse
|
medium | CVE-2020-10685 severity moderate: SUSE including 116 source package names (ansible-10-10.6.0-1.1, ansible-11-11.11.0-1.1, …), 248 product×package rows across 10 product lines (HPE Helion OpenStack 8, HPE Helion OpenStack Cloud 8, … (10 product lines)): Fixed 246, Known Not Affected 2. | https://www.suse.com/security/cve/CVE-2020-10685/ |
ubuntu
|
medium | CVE-2020-10685 medium priority: Ubuntu including 1 source packages (ansible), 17 status rows across 17 suites (bionic, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): not-affected 13, needed 2, ignored 1, released 1. | https://ubuntu.com/security/CVE-2020-10685 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| redhat | ansible_engine | >= 2.7.0, < 2.7.17 | cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:* |
| redhat | ansible_engine | >= 2.8.0, < 2.8.11 | cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:* |
| redhat | ansible_engine | >= 2.9.0, < 2.9.7 | cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:* |
| redhat | ansible_tower | <= 3.4.5 | cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:* |
| redhat | ansible_tower | >= 3.5.0, <= 3.5.5 | cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:* |
| redhat | ansible_tower | >= 3.6.0, <= 3.6.3 | cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:* |
| redhat | ceph_storage | 2.0 | cpe:2.3:a:redhat:ceph_storage:2.0:*:*:*:*:*:*:* |
| redhat | ceph_storage | 3.0 | cpe:2.3:a:redhat:ceph_storage:3.0:*:*:*:*:*:*:* |
| redhat | openstack | 10 | cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:* |
| redhat | openstack | 13 | cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:* |
| redhat | openstack | 15 | cpe:2.3:a:redhat:openstack:15:*:*:*:*:*:*:* |
| redhat | storage | 3.0 | cpe:2.3:a:redhat:storage:3.0:*:*:*:*:*:*:* |
| debian | debian_linux | 10.0 | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10685 | Issue Tracking Patch Vendor Advisory |
| https://github.com/ansible/ansible/pull/68433 | Patch Third Party Advisory |
| https://security.gentoo.org/glsa/202006-11 | Third Party Advisory |
| https://www.debian.org/security/2021/dsa-4950 | Third Party Advisory |