Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-10875

Опубликовано: 13 июл. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 4.6
CVSS3: 7.8

Описание

A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.

РелизСтатусПримечание
artful

ignored

end of life
bionic

released

2.5.1+dfsg-1ubuntu0.1
cosmic

not-affected

2.6.1+dfsg-1
devel

not-affected

2.6.1+dfsg-1
disco

not-affected

2.6.1+dfsg-1
eoan

not-affected

2.6.1+dfsg-1
esm-apps/bionic

released

2.5.1+dfsg-1ubuntu0.1
esm-apps/focal

not-affected

2.6.1+dfsg-1
esm-apps/jammy

not-affected

2.6.1+dfsg-1
esm-apps/noble

not-affected

2.6.1+dfsg-1

Показывать по

4.6 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
больше 7 лет назад

A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.

CVSS3: 7.8
nvd
больше 7 лет назад

A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.

CVSS3: 7.8
debian
больше 7 лет назад

A flaw was found in ansible. ansible.cfg is read from the current work ...

CVSS3: 7.8
github
больше 3 лет назад

Ansible Arbitrary Code Execution

CVSS3: 9.8
fstec
больше 7 лет назад

Уязвимость системы управления конфигурациями Ansible, связанная с отсутствием контроля пути поиска конфигурационного файла ansible.cfg, позволяющая нарушителю выполнить произвольный код

4.6 Medium

CVSS2

7.8 High

CVSS3