Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wqq5-c89p-3wc3

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Ansible Arbitrary Code Execution

Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which allows remote attackers to execute arbitrary code via (1) crafted lookup('pipe') calls or (2) crafted Jinja2 data.

Пакеты

Наименование

ansible

pip
Затронутые версииВерсия исправления

< 1.6.7

1.6.7

EPSS

Процентиль: 89%
0.04747
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 6 лет назад

Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which allows remote attackers to execute arbitrary code via (1) crafted lookup('pipe') calls or (2) crafted Jinja2 data.

CVSS3: 9.8
nvd
почти 6 лет назад

Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which allows remote attackers to execute arbitrary code via (1) crafted lookup('pipe') calls or (2) crafted Jinja2 data.

CVSS3: 9.8
debian
почти 6 лет назад

Ansible before 1.6.7 does not prevent inventory data with "{{" and "lo ...

EPSS

Процентиль: 89%
0.04747
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-74