Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p62g-jhg6-v3rq

Опубликовано: 07 апр. 2021
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 7.1

Описание

Code Injection, Race Condition, and Execution with Unnecessary Privileges in Ansible

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.11, and 2.9.7 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.

Пакеты

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.7.0a1, < 2.7.17

2.7.17

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.8.0a1, < 2.8.11

2.8.11

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.9.0a1, < 2.9.7

2.9.7

EPSS

Процентиль: 6%
0.00024
Низкий

6.9 Medium

CVSS4

7.1 High

CVSS3

Дефекты

CWE-250
CWE-362
CWE-862
CWE-94

Связанные уязвимости

CVSS3: 7.9
ubuntu
почти 6 лет назад

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.

CVSS3: 7.9
redhat
почти 6 лет назад

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.

CVSS3: 7.9
nvd
почти 6 лет назад

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.

CVSS3: 7.9
debian
почти 6 лет назад

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9. ...

fstec
почти 6 лет назад

Уязвимость системы управления конфигурациями Ansible, связанная с ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

EPSS

Процентиль: 6%
0.00024
Низкий

6.9 Medium

CVSS4

7.1 High

CVSS3

Дефекты

CWE-250
CWE-362
CWE-862
CWE-94