Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-10874

Опубликовано: 02 июл. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 4.6
CVSS3: 7.8

Описание

In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.

РелизСтатусПримечание
artful

ignored

end of life
bionic

released

2.5.1+dfsg-1ubuntu0.1
cosmic

not-affected

2.6.1+dfsg-1
devel

not-affected

2.6.1+dfsg-1
disco

not-affected

2.6.1+dfsg-1
eoan

not-affected

2.6.1+dfsg-1
esm-apps/bionic

released

2.5.1+dfsg-1ubuntu0.1
esm-apps/focal

not-affected

2.6.1+dfsg-1
esm-apps/jammy

not-affected

2.6.1+dfsg-1
esm-apps/noble

not-affected

2.6.1+dfsg-1

Показывать по

4.6 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
больше 7 лет назад

In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.

CVSS3: 7.8
nvd
больше 7 лет назад

In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.

CVSS3: 7.8
debian
больше 7 лет назад

In ansible it was found that inventory variables are loaded from curre ...

CVSS3: 7.8
github
больше 3 лет назад

Ansible Improper Input Validation vulnerability

CVSS3: 7.8
fstec
больше 7 лет назад

Уязвимость системы управления конфигурациями Ansible, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код

4.6 Medium

CVSS2

7.8 High

CVSS3