A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.
CVSS Details
- CVSS 3.1 Base Score: 7.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade ansibleUpgrade ansible-doc | Sep 28, 2023 | Mar 24, 2020 |
| Debian | — | Upgrade ansible | Aug 9, 2021 | Mar 24, 2020 |
| Gentoo Linux | — | Upgrade app-admin/ansible. | Jun 15, 2020 | Mar 24, 2020 |
| Suse | — | Upgrade ansible-testUpgrade ansible-docUpgrade ansible | Mar 19, 2022 | Mar 24, 2020 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 24, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 24, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub