Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6j58-grhv-2769

Опубликовано: 25 авг. 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

ansible-runner vulnerable to shell command injection

A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters getting executed as host's shell command. A developer could unintentionally write code that gets executed in the host rather than the virtual environment.

Пакеты

Наименование

ansible-runner

pip
Затронутые версииВерсия исправления

< 2.1.0

2.1.0

EPSS

Процентиль: 20%
0.00063
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-116
CWE-20

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 3 лет назад

A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters getting executed as host's shell command. A developer could unintentionally write code that gets executed in the host rather than the virtual environment.

CVSS3: 7.3
redhat
около 4 лет назад

A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters getting executed as host's shell command. A developer could unintentionally write code that gets executed in the host rather than the virtual environment.

CVSS3: 7.8
nvd
больше 3 лет назад

A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters getting executed as host's shell command. A developer could unintentionally write code that gets executed in the host rather than the virtual environment.

CVSS3: 7.8
debian
больше 3 лет назад

A flaw was found in ansible-runner. An improper escaping of the shell ...

EPSS

Процентиль: 20%
0.00063
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-116
CWE-20