Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10875

Опубликовано: 13 июл. 2018
Источник: debian

Описание

A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ansiblefixed2.6.1+dfsg-1package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1596533

  • https://github.com/ansible/ansible/pull/42070

  • https://github.com/ansible/ansible/commit/4cecbe81adbc655d7ab734165d3ac539f8ba5981

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.

CVSS3: 7.8
redhat
больше 7 лет назад

A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.

CVSS3: 7.8
nvd
больше 7 лет назад

A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.

CVSS3: 7.8
github
больше 3 лет назад

Ansible Arbitrary Code Execution

CVSS3: 9.8
fstec
больше 7 лет назад

Уязвимость системы управления конфигурациями Ansible, связанная с отсутствием контроля пути поиска конфигурационного файла ansible.cfg, позволяющая нарушителю выполнить произвольный код