PT-2020-7689 · Ansible+1 · Ansible+2
Jimi-C
·
Published
2014-07-26
·
Updated
2026-06-03
·
CVE-2014-4967
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ansible versions prior to 1.6.7
Description
The issue allows remote attackers to execute arbitrary code by leveraging access to an Ansible managed host and providing a crafted fact. This can be achieved with a fact that includes specific clauses, such as a trailing
src= clause, a trailing temp= clause, or a trailing validate= clause accompanied by a shell command.Recommendations
For versions prior to 1.6.7, update to version 1.6.7 or later to resolve the issue. As a temporary workaround, consider restricting access to managed hosts and validating all facts to prevent the execution of arbitrary code. Avoid using facts with trailing clauses such as
src=, temp=, or validate= accompanied by shell commands until the issue is resolved.Fix
RCE
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Ansible
Ansible-Core