Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10874

Опубликовано: 29 июн. 2018
Источник: redhat
CVSS3: 7.8

Описание

In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.

Отчет

Red Hat Gluster Storage 3 and Red Hat Ceph Storage 3 ships the affected version of ansible, but they no longer maintain their own version of ansible. Both the products will consume fixes directly from ansible repository.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5ansibleNot affected
Red Hat Ceph Storage 2ansibleAffected
Red Hat Ceph Storage 3ansibleAffected
Red Hat OpenShift Enterprise 3ansibleWill not fix
Red Hat OpenStack Platform 14 (Rocky)ansibleNot affected
Red Hat Satellite 6ansibleNot affected
Red Hat Storage 3ansibleAffected
Red Hat Ansible Engine 2.4 for RHEL 7ansibleFixedRHSA-2018:215210.07.2018
Red Hat Ansible Engine 2.5 for RHEL 7ansibleFixedRHSA-2018:215010.07.2018
Red Hat Ansible Engine 2.6 for RHEL 7ansibleFixedRHSA-2018:216610.07.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1596528ansible: Inventory variables are loaded from current working directory when running ad-hoc command that can lead to code execution

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.

CVSS3: 7.8
nvd
больше 7 лет назад

In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.

CVSS3: 7.8
debian
больше 7 лет назад

In ansible it was found that inventory variables are loaded from curre ...

CVSS3: 7.8
github
больше 3 лет назад

Ansible Improper Input Validation vulnerability

CVSS3: 7.8
fstec
больше 7 лет назад

Уязвимость системы управления конфигурациями Ansible, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код

7.8 High

CVSS3