CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2020-10685: A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when using modules which decrypts vault files such as assemble, script, unarchive, win_copy, aws_s3 or copy modules. The temporary directory is created in /tmp leaves the s ts unencrypted. On Operating Systems which /tmp is not a tmpfs but part of the root partition,

mediumCVSS 5CVE-2020-10685

CSIRTS triage

vendor: Red Hatproduct: Ansible EngineInformation disclosureaffected: 2.7.x before 2.7.17, 2.8.x before 2.8.11, 2.9.x before 2.9.7; Ansible Tower 3.4.5, 3.5.5, 3.6.3 and earlier
What
Vault file decryption modules expose sensitive information by improper handling of decrypted content.
Who is affected
Ansible Engine deployments using vault decryption modules (assemble, script, etc.) on affected versions.
Urgency
Medium priority; information disclosure of encrypted secrets when using affected modules.
Action
Update Ansible Engine to 2.7.17, 2.8.11, 2.9.7 or later, and Ansible Tower to patched version.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Ansible Engine

Get an email when a new Ansible Engine advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
medium — CVSS 5
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-10685

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2020-10685coverage & exploitation statusNVD · CVE.org

More from Microsoft Security Response Center