In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.
2018-07-02T13:29:00.367
2024-11-21T03:42:11.677
Modified
CVSSv3.0: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | ansible_engine | 2.0 | Yes |
Application | redhat | ansible_engine | 2.4 | Yes |
Application | redhat | ansible_engine | 2.5 | Yes |
Application | redhat | ansible_engine | 2.6 | Yes |
Application | redhat | openstack | 10 | Yes |
Application | redhat | openstack | 12 | Yes |
Application | redhat | openstack | 13 | Yes |
Application | redhat | virtualization | 4.0 | Yes |
Application | redhat | virtualization_host | 4.0 | Yes |