PT-2018-5036 · Red Hat+2 · Ansible+2

Adam Mariš

·

Published

2017-03-30

·

Updated

2024-05-06

·

CVE-2016-8628

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Ansible versions prior to 2.2.0
Description The issue arises from improper sanitization of fact variables sent from the Ansible controller. An attacker who can create special variables on the controller may be able to execute arbitrary commands on Ansible clients, running them as the user Ansible is set to run as.
Recommendations For versions prior to 2.2.0, update to version 2.2.0 or later to resolve the issue.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1386
CVE-2016-8628
GHSA-JG4F-JQM5-4MGQ
OPENSUSE-SU-2017:2976-1
OPENSUSE-SU-2017:2978-1
PYSEC-2018-38
RHSA-2016:2778
SUSE-SU-2020:3309-1
SUSE-SU-2024:1509-1

Affected Products

Alt Linux
Ansible
Ansible-Core