Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-8628

Опубликовано: 31 июл. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 9
CVSS3: 7.6

Описание

Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the user Ansible runs as.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

2.5.1+dfsg-1
devel

not-affected

2.6.1+dfsg-1
esm-apps/bionic

not-affected

2.5.1+dfsg-1
esm-apps/xenial

released

2.0.0.2-2ubuntu1.1
esm-infra-legacy/trusty

not-affected

code not present
precise

DNE

precise/esm

DNE

trusty

not-affected

code not present
trusty/esm

not-affected

code not present

Показывать по

9 Critical

CVSS2

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 7.6
redhat
больше 9 лет назад

Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the user Ansible runs as.

CVSS3: 7.6
nvd
больше 7 лет назад

Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the user Ansible runs as.

CVSS3: 7.6
debian
больше 7 лет назад

Ansible before version 2.2.0 fails to properly sanitize fact variables ...

CVSS3: 9.1
github
больше 7 лет назад

Ansible fails to properly sanitize fact variables sent from the Ansible controller

suse-cvrf
почти 2 года назад

Security update for SUSE Manager Client Tools

9 Critical

CVSS2

7.6 High

CVSS3