PT-2020-7685 · Ansible+1 · Ansible+2

Florian Weimer

·

Published

2014-07-26

·

Updated

2022-05-24

·

CVE-2014-4678

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ansible versions prior to 1.6.4
Description The issue is related to the safe eval function, which does not properly restrict the code subset. This allows remote attackers to execute arbitrary code via crafted instructions.
Recommendations For versions prior to 1.6.4, update to version 1.6.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the safe eval function until a patch is available.

Fix

RCE

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1957
CVE-2014-4678
GHSA-66C7-5PWV-MM3J
MGASA-2014-0350
PYSEC-2020-203

Affected Products

Alt Linux
Ansible
Ansible-Core