PT-2015-6343 · Red Hat+4 · Ansible+4

Cory Benfield

·

Published

2015-06-27

·

Updated

2026-06-03

·

CVE-2015-3908

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ansible versions prior to 1.9.2
Description The issue concerns a failure to verify that the server hostname matches a domain name in the subject's Common Name (CN) or the subjectAltName field of the X.509 certificate. This allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Recommendations For Ansible versions prior to 1.9.2, update to version 1.9.2 or later to resolve the issue. As a temporary workaround, consider restricting SSL connections to only trusted servers or implementing additional verification measures for server certificates until the update can be applied.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1579
CVE-2015-3908
DLA-1923-1
GHSA-W64C-PXJJ-H866
MGASA-2015-0292
OPENSUSE-SU-2024:10326-1
OPENSUSE-SU-2024:14244-1
OPENSUSE-SU-2024:14536-1
OPENSUSE-SU-2025:15605-1
OPENSUSE-SU-2025:15753-1
OPENSUSE-SU-2026:10944-1
PYSEC-2015-1
USN-7330-1
USN-7330-2

Affected Products

Alt Linux
Ansible
Ansible-Core
Linuxmint
Ubuntu