Количество 8
Количество 8
GHSA-w8p5-mx5w-cpqj
ansible-core: Argument injection in ansible-galaxy role install leads to arbitrary code execution
CVE-2026-11332
A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.
CVE-2026-11332
A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.
CVE-2026-11332
A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.
CVE-2026-11332
Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution
CVE-2026-11332
A flaw was found in ansible-core. The ansible-galaxy role install comm ...
openSUSE-SU-2026:21097-1
Security update for ansible-core
SUSE-SU-2026:2680-1
Security update for ansible-core
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-w8p5-mx5w-cpqj ansible-core: Argument injection in ansible-galaxy role install leads to arbitrary code execution | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-11332 A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-11332 A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-11332 A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-11332 Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-11332 A flaw was found in ansible-core. The ansible-galaxy role install comm ... | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
openSUSE-SU-2026:21097-1 Security update for ansible-core | 0% Низкий | около 2 месяцев назад | ||
SUSE-SU-2026:2680-1 Security update for ansible-core | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу