Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9587

Опубликовано: 09 янв. 2017
Источник: redhat
CVSS3: 6.6
CVSS2: 6.8
EPSS Средний

Описание

Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.

An input validation vulnerability was found in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 11 (Ocata)ansibleAffected
Red Hat Quickstart Cloud Installer 1ansibleWill not fix
Red Hat Gluster Storage 3.1 for RHEL 7ansibleFixedRHSA-2017:026007.02.2017
Red Hat Gluster Storage 3.1 for RHEL 7gdeployFixedRHSA-2017:026007.02.2017
Red Hat Gluster Storage 3.1 for RHEL 7python-passlibFixedRHSA-2017:026007.02.2017
Red Hat OpenShift Container Platform 3.2ansibleFixedRHSA-2017:044806.03.2017
Red Hat OpenShift Container Platform 3.2openshift-ansibleFixedRHSA-2017:044806.03.2017
Red Hat OpenShift Container Platform 3.3ansibleFixedRHSA-2017:044806.03.2017
Red Hat OpenShift Container Platform 3.3openshift-ansibleFixedRHSA-2017:044806.03.2017
Red Hat OpenShift Container Platform 3.4ansibleFixedRHSA-2017:044806.03.2017

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1404378Ansible: Compromised remote hosts can lead to running commands on the Ansible controller

EPSS

Процентиль: 97%
0.17789
Средний

6.6 Medium

CVSS3

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 8 лет назад

Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.

CVSS3: 8.1
nvd
больше 8 лет назад

Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.

CVSS3: 8.1
debian
больше 8 лет назад

Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper inpu ...

CVSS3: 8.1
github
почти 8 лет назад

Ansible is vulnerable to an improper input validation in Ansible's handling of data sent from client systems

suse-cvrf
больше 2 лет назад

Security update for SUSE Manager Client Tools

EPSS

Процентиль: 97%
0.17789
Средний

6.6 Medium

CVSS3

6.8 Medium

CVSS2