PT-2020-7689 · Ansible+1 · Ansible+2

Jimi-C

·

Published

2014-07-26

·

Updated

2026-06-03

·

CVE-2014-4967

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ansible versions prior to 1.6.7
Description The issue allows remote attackers to execute arbitrary code by leveraging access to an Ansible managed host and providing a crafted fact. This can be achieved with a fact that includes specific clauses, such as a trailing src= clause, a trailing temp= clause, or a trailing validate= clause accompanied by a shell command.
Recommendations For versions prior to 1.6.7, update to version 1.6.7 or later to resolve the issue. As a temporary workaround, consider restricting access to managed hosts and validating all facts to prevent the execution of arbitrary code. Avoid using facts with trailing clauses such as src=, temp=, or validate= accompanied by shell commands until the issue is resolved.

Fix

RCE

Special Elements Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1957
CVE-2014-4967
GHSA-64CW-M57J-65XJ
MGASA-2014-0350
OPENSUSE-SU-2024:10326-1
OPENSUSE-SU-2024:14244-1
OPENSUSE-SU-2024:14536-1
OPENSUSE-SU-2025:15605-1
OPENSUSE-SU-2025:15753-1
OPENSUSE-SU-2026:10944-1
PYSEC-2020-205

Affected Products

Alt Linux
Ansible
Ansible-Core