Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-11332

Опубликовано: 05 июн. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.

Отчет

Conditions for Exploitation: Successful exploitation requires user interaction, specifically tricking a victim into installing a maliciously crafted Ansible role (or a role with a malicious dependency) using the ansible-galaxy role install command. Broad Impact: While user interaction is required, the potential impact is highly severe. Successfully injecting the malicious arguments allows a remote attacker to achieve arbitrary code execution on the machine running the Ansible command, leading to a full compromise of the user's environment and system integrity.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 8mta/mta-rhel9-operatorAffected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-rhel9-operatorAffected
Migration Toolkit for Virtualizationmtv-candidate/mtv-rhel9-operatorWill not fix
OpenShift Service Mesh 3openshift-service-mesh/kiali-rhel9-operatorNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-operator-bundleWill not fix
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-rhel9Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/hub-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/controller-rhel8-operatorAffected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/de-minimal-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/de-supported-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2485379ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution

EPSS

Процентиль: 12%
0.00214
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
2 месяца назад

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.

CVSS3: 7.8
nvd
2 месяца назад

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.

CVSS3: 7.8
msrc
2 месяца назад

Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution

CVSS3: 7.8
debian
2 месяца назад

A flaw was found in ansible-core. The ansible-galaxy role install comm ...

suse-cvrf
около 2 месяцев назад

Security update for ansible-core

EPSS

Процентиль: 12%
0.00214
Низкий

7.8 High

CVSS3