PT-2015-6343 · Red Hat+4 · Ansible+4

Cory Benfield

·

Publicado

2015-06-27

·

Atualizado

2026-06-03

·

CVE-2015-3908

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ansible versions prior to 1.9.2
Description The issue concerns a failure to verify that the server hostname matches a domain name in the subject's Common Name (CN) or the subjectAltName field of the X.509 certificate. This allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Recommendations For Ansible versions prior to 1.9.2, update to version 1.9.2 or later to resolve the issue. As a temporary workaround, consider restricting SSL connections to only trusted servers or implementing additional verification measures for server certificates until the update can be applied.

Correção

Insufficient Verification of Data Authenticity

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1579
CVE-2015-3908
DLA-1923-1
GHSA-W64C-PXJJ-H866
MGASA-2015-0292
OPENSUSE-SU-2024:10326-1
OPENSUSE-SU-2024:14244-1
OPENSUSE-SU-2024:14536-1
OPENSUSE-SU-2025:15605-1
OPENSUSE-SU-2025:15753-1
OPENSUSE-SU-2026:10944-1
PYSEC-2015-1
USN-7330-1
USN-7330-2

Produtos afetados

Alt Linux
Ansible
Ansible-Core
Linuxmint
Ubuntu