CVE-2020-10685: Exposure of Resource to Wrong Sphere
(updated )
A flaw was found in Ansible when using modules which decrypts vault files. The temporary directory is created in /tmp
and left unecrypted.
References
Detect and mitigate CVE-2020-10685 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →