Medium severity5.0NVD Advisory· Published Oct 5, 2020· Updated Jun 17, 2026
CVE-2020-25635
CVE-2020-25635
Description
A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed. Files would remain in the bucket exposing the data. This issue affects directly data confidentiality.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ansiblePyPI | < 2.10.1 | 2.10.1 |
Affected products
3- AWS Community/Community Collectionsv5Range: from 1.0.0 to 1.2.0
Patches
Vulnerability mechanics
References
6- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-f556-49jc-4rvcghsaADVISORY
- github.com/ansible-collections/community.aws/issues/222nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-25635ghsaADVISORY
- github.com/ansible-collections/community.aws/pull/237ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2020-220.yamlghsaWEB
News mentions
0No linked articles in our index yet.