A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
2020-03-16T16:15:14.093
2024-11-21T05:11:16.820
Modified
CVSSv3.1: 3.9 (LOW)
AV:L/AC:H/Au:N/C:N/I:P/A:P
1.9
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | ansible | ≤ 2.7.16 | Yes |
Application | redhat | ansible | ≤ 2.8.8 | Yes |
Application | redhat | ansible | ≤ 2.9.5 | Yes |
Application | redhat | ansible_tower | ≤ 3.3.4 | Yes |
Application | redhat | ansible_tower | ≤ 3.4.5 | Yes |
Application | redhat | ansible_tower | ≤ 3.5.5 | Yes |
Application | redhat | ansible_tower | ≤ 3.6.3 | Yes |
Application | redhat | cloudforms_management_engine | 5.0 | Yes |
Application | redhat | openstack | 13 | Yes |