Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w8p5-mx5w-cpqj

Опубликовано: 05 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

ansible-core: Argument injection in ansible-galaxy role install leads to arbitrary code execution

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.

Пакеты

Наименование

ansible-core

pip
Затронутые версииВерсия исправления

< 2.16.19rc1

2.16.19rc1

Наименование

ansible-core

pip
Затронутые версииВерсия исправления

>= 2.17.0b1, < 2.18.18rc1

2.18.18rc1

Наименование

ansible-core

pip
Затронутые версииВерсия исправления

>= 2.19.0b1, < 2.19.11rc1

2.19.11rc1

Наименование

ansible-core

pip
Затронутые версииВерсия исправления

>= 2.20.0b1, < 2.20.7rc1

2.20.7rc1

Наименование

ansible-core

pip
Затронутые версииВерсия исправления

>= 2.21.0b1, < 2.21.1rc1

2.21.1rc1

EPSS

Процентиль: 12%
0.00214
Низкий

7.8 High

CVSS3

Дефекты

CWE-88

Связанные уязвимости

CVSS3: 7.8
ubuntu
2 месяца назад

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.

CVSS3: 7.8
redhat
2 месяца назад

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.

CVSS3: 7.8
nvd
2 месяца назад

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.

CVSS3: 7.8
msrc
2 месяца назад

Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution

CVSS3: 7.8
debian
2 месяца назад

A flaw was found in ansible-core. The ansible-galaxy role install comm ...

EPSS

Процентиль: 12%
0.00214
Низкий

7.8 High

CVSS3

Дефекты

CWE-88