VulnerabilityModified
CVE-2016-8628
An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the user Ansible runs as.
CRITICAL 9.1EPSS 3.25%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.25%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the user Ansible runs as.
- CVSS 3.0
- 9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 3.25% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- redhat/ansible
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/94109Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2016:2778Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8628Issue Tracking, Third Party Advisory
- http://www.securityfocus.com/bid/94109Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2016:2778Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8628Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.