Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-1734

Опубликовано: 03 мар. 2020
Источник: nvd
CVSS3: 7.4
CVSS2: 3.7
EPSS Низкий

Описание

A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could take advantage and run arbitrary commands by overwriting the ansible facts.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:*
Версия до 2.7.16 (включая)
cpe:2.3:a:redhat:ansible_engine:2.8.8:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_engine:2.9.5:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:*
Версия до 3.3.4 (включая)
cpe:2.3:a:redhat:ansible_tower:3.4.5:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_tower:3.5.5:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_tower:3.6.3:*:*:*:*:*:*:*

EPSS

Процентиль: 33%
0.00131
Низкий

7.4 High

CVSS3

3.7 Low

CVSS2

Дефекты

CWE-78
CWE-78

Связанные уязвимости

CVSS3: 7.4
ubuntu
почти 6 лет назад

A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could take advantage and run arbitrary commands by overwriting the ansible facts.

CVSS3: 7.4
redhat
почти 6 лет назад

A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could take advantage and run arbitrary commands by overwriting the ansible facts.

CVSS3: 7.4
debian
почти 6 лет назад

A flaw was found in the pipe lookup plugin of ansible. Arbitrary comma ...

CVSS3: 7.4
github
почти 4 года назад

OS Command Injection in ansible

CVSS3: 7.4
fstec
почти 6 лет назад

Уязвимость системы управления конфигурациями Ansible, связанная с неприятием мер по нейтрализации специальных элементов, используемых в команде ОС, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

EPSS

Процентиль: 33%
0.00131
Низкий

7.4 High

CVSS3

3.7 Low

CVSS2

Дефекты

CWE-78
CWE-78