Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-64cw-m57j-65xj

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Ansible Arbitrary Code Execution

Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansible managed host and providing a crafted fact, as demonstrated by a fact with (1) a trailing " src=" clause, (2) a trailing " temp=" clause, or (3) a trailing " validate=" clause accompanied by a shell command.

Пакеты

Наименование

ansible

pip
Затронутые версииВерсия исправления

< 1.6.7

1.6.7

EPSS

Процентиль: 89%
0.04747
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 6 лет назад

Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansible managed host and providing a crafted fact, as demonstrated by a fact with (1) a trailing " src=" clause, (2) a trailing " temp=" clause, or (3) a trailing " validate=" clause accompanied by a shell command.

CVSS3: 9.8
nvd
почти 6 лет назад

Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansible managed host and providing a crafted fact, as demonstrated by a fact with (1) a trailing " src=" clause, (2) a trailing " temp=" clause, or (3) a trailing " validate=" clause accompanied by a shell command.

CVSS3: 9.8
debian
почти 6 лет назад

Multiple argument injection vulnerabilities in Ansible before 1.6.7 al ...

EPSS

Процентиль: 89%
0.04747
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-74