{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-10T14:32:25.543","vulnerabilities":[{"cve":{"id":"CVE-2020-14365","sourceIdentifier":"secalert@redhat.com","published":"2020-09-23T13:15:15.470","lastModified":"2024-11-21T05:03:06.050","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability."},{"lang":"es","value":"Se encontró un fallo en Ansible Engine, en ansible-engine versiones 2.8.x anteriores a 2.8.15 y ansible-engine versiones 2.9.x anteriores a 2.9.13, Cuando se instalan paquetes usando el módulo dnf.&#xa0;Unas firmas GPG son ignoradas durante la instalación incluso cuando disable_gpg_check es establecida en False, que es el comportamiento predeterminado.&#xa0;Este fallo  conlleva a que son instalados paquetes maliciosos en el sistema y son ejecutados códigos arbitrarios por medio de scripts de instalación de paquetes.&#xa0;La mayor amenaza de esta vulnerabilidad es la integridad y la disponibilidad del sistema"}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:C/A:C","baseScore":6.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":9.2,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-347"}]},{"source":"nvd@nist.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-347"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:*","versionStartIncluding":"2.8.0","versionEndIncluding":"2.8.15","matchCriteriaId":"128A8518-1B23-4263-8958-2A3813E70EAD"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:*","versionStartIncluding":"2.9.0","versionEndIncluding":"2.9.13","matchCriteriaId":"2633DB82-E043-4132-9493-B4CBB25FAE82"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:*","versionStartIncluding":"3.6.0","versionEndIncluding":"3.6.5","matchCriteriaId":"8EA99A5E-25E4-42A8-92D3-017734DA0AA7"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7.0","versionEndIncluding":"3.7.2","matchCriteriaId":"DDE01259-A945-4567-AB95-8DAB087A686A"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:ansible_tower:3.0:*:*:*:*:*:*:*","matchCriteriaId":"B31C575C-06D2-4CAF-A5B7-B9469B3ED55F"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:ceph_storage:2.0:*:*:*:*:*:*:*","matchCriteriaId":"D07DF15E-FE6B-4DAF-99BB-2147CF7D7EEA"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:ceph_storage:3.0:*:*:*:*:*:*:*","matchCriteriaId":"516F4E8E-ED2F-4282-9DAB-D8B378F61258"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:openstack_platform:10.0:*:*:*:*:*:*:*","matchCriteriaId":"542B31BD-5767-4B33-9201-40548D1223B3"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:openstack_platform:13.0:*:*:*:*:*:*:*","matchCriteriaId":"C52600BF-9E87-4CD2-91F3-685AFE478C1E"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","matchCriteriaId":"07B237A9-69A3-4A9C-9DA0-4E06BD37AE73"}]}]}],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1869154","source":"secalert@redhat.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://www.debian.org/security/2021/dsa-4950","source":"secalert@redhat.com","tags":["Third Party Advisory"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1869154","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://www.debian.org/security/2021/dsa-4950","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}