Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f85h-23mf-2fwh

Опубликовано: 09 фев. 2022
Источник: github
Github: Прошло ревью
CVSS4: 1
CVSS3: 3.9

Описание

Argument Injection in Ansible

A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

Пакеты

Наименование

ansible

pip
Затронутые версииВерсия исправления

<= 2.7.16

Отсутствует

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.8.0a1, <= 2.8.10

Отсутствует

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.9.0a1, <= 2.9.6

Отсутствует

EPSS

Процентиль: 31%
0.00384
Низкий

1 Low

CVSS4

3.9 Low

CVSS3

Дефекты

CWE-88

Связанные уязвимости

CVSS3: 3.9
ubuntu
больше 6 лет назад

A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

CVSS3: 3.9
redhat
больше 6 лет назад

A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

CVSS3: 3.9
nvd
больше 6 лет назад

A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

CVSS3: 3.9
debian
больше 6 лет назад

A flaw was found in Ansible Engine when the module package or service ...

suse-cvrf
больше 4 лет назад

Security update for ansible

EPSS

Процентиль: 31%
0.00384
Низкий

1 Low

CVSS4

3.9 Low

CVSS3

Дефекты

CWE-88