Описание
Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the user Ansible runs as.
Ansible fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the user Ansible runs as.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Gluster Storage 3.1 | ansible | Not affected | ||
| Red Hat OpenStack Platform 10 (Newton) | ansible | Not affected | ||
| Red Hat Quickstart Cloud Installer 1 | ansible | Affected | ||
| Red Hat Storage Console 2 | ansible | Not affected | ||
| Red Hat OpenShift Container Platform 3.2 | ansible | Fixed | RHSA-2016:2778 | 15.11.2016 |
| Red Hat OpenShift Container Platform 3.2 | openshift-ansible | Fixed | RHSA-2016:2778 | 15.11.2016 |
| Red Hat OpenShift Container Platform 3.3 | ansible | Fixed | RHSA-2016:2778 | 15.11.2016 |
| Red Hat OpenShift Container Platform 3.3 | openshift-ansible | Fixed | RHSA-2016:2778 | 15.11.2016 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.6 High
CVSS3
6.8 Medium
CVSS2
Связанные уязвимости
Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the user Ansible runs as.
Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the user Ansible runs as.
Ansible before version 2.2.0 fails to properly sanitize fact variables ...
Ansible fails to properly sanitize fact variables sent from the Ansible controller
EPSS
7.6 High
CVSS3
6.8 Medium
CVSS2