Improper Neutralization of Special Elements in Output Used by a Downstream Component in Ansible - CVE-2014-4967
Published: February 18, 2020 / Updated: July 17, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansible managed host and providing a crafted fact, as demonstrated by a fact with (1) a trailing " src=" clause, (2) a trailing " temp=" clause, or (3) a trailing " validate=" clause accompanied by a shell command.
Affected software
Gentoo Linux
Fedora
ansible (Alpine package)
ansible
How to mitigate CVE-2014-4967
ansible (Alpine package) - update to 1.6.7-r0
ansible - addressed in versions 1.6.7-1.el6, 1.6.8-1.el6, 1.6.9-1.el6, 1.6.10-1.el6, 1.7-1.el6
External References
Related Security Bulletins
- Multiple vulnerabilities in Ansible
- Improper Neutralization of Special Elements in Output Used by a Downstream Component in ansible (Alpine package)
- Gentoo update for Ansible
- Fedora EPEL 6 update for ansible
- Fedora EPEL 6 update for ansible
- Fedora EPEL 6 update for ansible
- Fedora EPEL 6 update for ansible
- Fedora EPEL 6 update for ansible