Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

github логотип

GHSA-p62g-jhg6-v3rq

больше 5 лет назад

Code Injection, Race Condition, and Execution with Unnecessary Privileges in Ansible

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2020-10684

больше 6 лет назад

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.

CVSS3: 7.9
EPSS: Низкий
redhat логотип

CVE-2020-10684

больше 6 лет назад

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.

CVSS3: 7.9
EPSS: Низкий
nvd логотип

CVE-2020-10684

больше 6 лет назад

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.

CVSS3: 7.9
EPSS: Низкий
debian логотип

CVE-2020-10684

больше 6 лет назад

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9. ...

CVSS3: 7.9
EPSS: Низкий
fstec логотип

BDU:2020-05829

больше 6 лет назад

Уязвимость системы управления конфигурациями Ansible, связанная с ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

CVSS2: 3.6
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:0081-1

больше 4 лет назад

Security update for ansible

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-p62g-jhg6-v3rq

Code Injection, Race Condition, and Execution with Unnecessary Privileges in Ansible

CVSS3: 7.1
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-10684

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.

CVSS3: 7.9
0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-10684

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.

CVSS3: 7.9
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2020-10684

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.

CVSS3: 7.9
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2020-10684

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9. ...

CVSS3: 7.9
0%
Низкий
больше 6 лет назад
fstec логотип
BDU:2020-05829

Уязвимость системы управления конфигурациями Ansible, связанная с ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

CVSS2: 3.6
0%
Низкий
больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2022:0081-1

Security update for ansible

больше 4 лет назад

Уязвимостей на страницу