Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qg47-5px9-32g7

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Ansible Remote Code Execution

The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.

Пакеты

Наименование

ansible

pip
Затронутые версииВерсия исправления

< 1.5.4

1.5.4

EPSS

Процентиль: 84%
0.02239
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 6 лет назад

The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.

CVSS3: 9.8
redhat
почти 12 лет назад

The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.

CVSS3: 9.8
nvd
почти 6 лет назад

The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.

CVSS3: 9.8
debian
почти 6 лет назад

The safe_eval function in Ansible before 1.5.4 does not properly restr ...

EPSS

Процентиль: 84%
0.02239
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-20