Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c2w9-48qc-qpj4

Опубликовано: 13 июл. 2018
Источник: github
Github: Прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

Code injection in ansible

An exploitable vulnerability exists in the yaml loading functionality of ansible-vault before 1.0.5. A specially crafted vault can execute arbitrary python commands resulting in command execution. An attacker can insert python into the vault to trigger this vulnerability.

Пакеты

Наименование

ansible-vault

pip
Затронутые версииВерсия исправления

< 1.0.5

1.0.5

EPSS

Процентиль: 71%
0.00664
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.5
nvd
больше 8 лет назад

An exploitable vulnerability exists in the yaml loading functionality of ansible-vault before 1.0.5. A specially crafted vault can execute arbitrary python commands resulting in command execution. An attacker can insert python into the vault to trigger this vulnerability.

EPSS

Процентиль: 71%
0.00664
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-94