Description
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1923-1 | ansible security update |
Debian DSA |
DSA-4396-1 | ansible security update |
EUVD |
EUVD-2018-0016 | A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code. |
Github GHSA |
GHSA-fc4h-467w-46rh | Ansible Arbitrary Code Execution |
Ubuntu USN |
USN-4072-1 | Ansible vulnerabilities |
References
History
No history.
Subscriptions
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Redhat
Subscribe
Ansible Engine
Subscribe
Ceph Storage
Subscribe
Enterprise Linux
Subscribe
Gluster Storage
Subscribe
Openshift
Subscribe
Openstack
Subscribe
Virtualization
Subscribe
Virtualization Host
Subscribe
Suse
Subscribe
Package Hub
Subscribe
Suse Linux Enterprise Server
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T07:46:47.518Z
Reserved: 2018-05-09T00:00:00.000Z
Link: CVE-2018-10875
No data.
Status : Modified
Published: 2018-07-13T22:29:00.220
Modified: 2024-11-21T03:42:11.830
Link: CVE-2018-10875
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN