CVE-2020-25636: Files or Directories Accessible to External Parties
(updated )
A flaw was found in Ansible Base when using the aws_ssm
connection plugin as there is no namespace separation for file transfers. Files are written directly to the root bucket, making possible to have collisions when running multiple ansible processes. This issue affects mainly the service availability.
References
Detect and mitigate CVE-2020-25636 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →