OS Command Injection in Ansible - CVE-2019-14905
Published: December 8, 2019 / Updated: January 24, 2020
Vulnerability details
The vulnerability allows a local user to execute arbitrary shell commands on the target system.
The vulnerability exists due to incorrect validation of filenames within the nxos_file_copy module when copying files to a flash or bootflash on NXOS devices using the remote_file parameter. A local user or malicious code can abuse this functionality to inject and execute arbitrary OS commands on the system with elevated privileges.
Affected software
ansible (Alpine package)
ansible
Fedora
SUSE Linux
Opensuse
How to mitigate CVE-2019-14905
ansible (Alpine package) - addressed in versions 2.7.16-r0, 2.8.8-r0
ansible - addressed in versions 2.9.3-1.el7, 2.9.3-1.el8, 2.9.3-1.fc30, 2.9.3-1.fc31