From edcea2c9d566aa6f5b6c276de9f50c9a8fa70c35 Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Sun, 31 May 2020 09:45:15 +0200 Subject: Update information on CVE-2020-1735/ansible --- data/CVE/list.2020 | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/data/CVE/list.2020 b/data/CVE/list.2020 index e9a22e65fc..896270c755 100644 --- a/data/CVE/list.2020 +++ b/data/CVE/list.2020 @@ -26845,12 +26845,15 @@ CVE-2020-1736 (A flaw was found in Ansible Engine when a file is moved using ato NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1802124 NOTE: https://github.com/ansible/ansible/issues/67794 CVE-2020-1735 (A flaw was found in the Ansible Engine when the fetch module is used. ...) - - ansible + - ansible 2.9.7+dfsg-1 [jessie] - ansible (No remote expansion in fetch module) NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1802085 NOTE: https://github.com/ansible/ansible/issues/67793 NOTE: https://github.com/ansible/ansible/pull/68720 NOTE: Introduced in https://github.com/ansible/ansible/commit/e47f6137e5b897dec4319e7cb7791fb9b2cffb8d (1.8) + NOTE: Fixed by: https://github.com/ansible/ansible/commit/290bfa820d533dc224e0c3fa7dd7c6b907ed0189 + NOTE: The commit has incorrect CVE reference adressed in + NOTE: https://github.com/ansible/ansible/commit/18f91bbb88a84b1d3614ef41c3550da735592ac1 CVE-2020-1734 (A flaw was found in the pipe lookup plugin of ansible. Arbitrary comma ...) - ansible (unimportant) NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1801804 -- cgit v1.2.3