Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-14905

Опубликовано: 31 мар. 2020
Источник: nvd
CVSS3: 7.3
CVSS3: 5.6
CVSS2: 4.6
EPSS Низкий

Описание

A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:*
Версия от 2.7.0 (включая) до 2.7.16 (исключая)
cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:*
Версия от 2.8.0 (включая) до 2.8.8 (исключая)
cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:*
Версия от 2.9.0 (включая) до 2.9.3 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:redhat:ansible_tower:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ceph_storage:3.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms_management_engine:5.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
Конфигурация 4

Одно из

cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

EPSS

Процентиль: 16%
0.0005
Низкий

7.3 High

CVSS3

5.6 Medium

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-20
CWE-668

Связанные уязвимости

CVSS3: 5.6
ubuntu
почти 6 лет назад

A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.

CVSS3: 5.6
redhat
около 6 лет назад

A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.

CVSS3: 5.6
debian
почти 6 лет назад

A vulnerability was found in Ansible Engine versions 2.9.x before 2.9. ...

CVSS3: 5.6
github
почти 5 лет назад

Externally Controlled Reference to a Resource in Another Sphere, Improper Input Validation, and External Control of File Name or Path in Ansible

CVSS3: 5.6
fstec
почти 6 лет назад

Уязвимость модуля nxos_file_copy системы управления конфигурациями Ansible, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 16%
0.0005
Низкий

7.3 High

CVSS3

5.6 Medium

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-20
CWE-668