debian · CVE-2020-1738

Quick triage

Priority: unimportant Published: Updated: Thu, 23 Jul 2026 01:18:52 GMT

View at Official debian advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2020-1738 unimportant priority: Debian including 1 source packages (ansible), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 5.

Description:

A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

cvelogic Threat Intelligence