In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ansible | Dec 12, 2019 | Jul 2, 2018 |
| Debian | — | Upgrade ansible | Jul 30, 2024 | Jul 2, 2018 |
| Suse | — | Upgrade ansibleUpgrade ansible-docUpgrade ansible-test | Aug 9, 2024 | Jul 2, 2018 |
| Ubuntu | — | Upgrade ansible | Jul 25, 2019 | Jul 2, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub