CVE-2016-9587
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 17.4%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 17.45% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- redhat/ansible · ansible/ansible · redhat/openstack
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2017-0195.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0260.htmlThird Party Advisory
- http://www.securityfocus.com/bid/95352Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:0448Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:0515Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1685Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9587Issue Tracking, Third Party Advisory
- https://security.gentoo.org/glsa/201701-77Third Party Advisory
- https://www.exploit-db.com/exploits/41013/Exploit, Third Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2017-0195.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0260.htmlThird Party Advisory
- http://www.securityfocus.com/bid/95352Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:0448Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:0515Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1685Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9587Issue Tracking, Third Party Advisory
- https://security.gentoo.org/glsa/201701-77Third Party Advisory
- https://www.exploit-db.com/exploits/41013/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.