Vulnerability record · CVE-2020-14365 · published 23 September 2020
CVE-2020-14365: Redhat ansible engine improper verification of cryptographic signature vulnerability
Redhat · Ansible Engine
A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.
Description
A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=1869154 | Issue TrackingVendor Advisory |
| https://www.debian.org/security/2021/dsa-4950 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1869154 | Issue TrackingVendor Advisory |
| https://www.debian.org/security/2021/dsa-4950 | Third Party Advisory |
Track CVE-2020-14365 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-14365), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.