Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a client system being managed by Ansible, and the ability to send facts back to the Ansible server, could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.
CVSS Details
- CVSS 3.1 Base Score: 8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ansible | Jul 30, 2024 | Jun 22, 2018 |
| Redhat Openshift | — | Upgrade openshift-ansibleUpgrade ansible | Jun 18, 2018 | Apr 11, 2017 |
| Suse | — | Upgrade ansible | Feb 4, 2022 | Nov 17, 2017 |
| Ubuntu | — | Upgrade ansible | Nov 19, 2024 | Jun 22, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub