Описание
The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.
Ссылки
- Release Notes
- Third Party AdvisoryVDB Entry
- Release Notes
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 1.5.4 (исключая)
cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
EPSS
Процентиль: 84%
0.02239
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-20
Связанные уязвимости
CVSS3: 9.8
ubuntu
почти 6 лет назад
The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.
CVSS3: 9.8
redhat
почти 12 лет назад
The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.
CVSS3: 9.8
debian
почти 6 лет назад
The safe_eval function in Ansible before 1.5.4 does not properly restr ...
EPSS
Процентиль: 84%
0.02239
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-20