Improper Neutralization of Special Elements in Output Used by a Downstream Component in Ansible - CVE-2014-4967

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in Ansible - CVE-2014-4967

Published: February 18, 2020 / Updated: July 17, 2020


Vulnerability identifier: #VU30363
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-4967
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansible managed host and providing a crafted fact, as demonstrated by a fact with (1) a trailing " src=" clause, (2) a trailing " temp=" clause, or (3) a trailing " validate=" clause accompanied by a shell command.


Affected software

Ansible
Gentoo Linux
Fedora
ansible (Alpine package)
ansible

How to mitigate CVE-2014-4967

Install update from vendor's website.

Ansible - update to 1.6.7
ansible (Alpine package) - update to 1.6.7-r0
ansible - addressed in versions 1.6.7-1.el6, 1.6.8-1.el6, 1.6.9-1.el6, 1.6.10-1.el6, 1.7-1.el6

External References

Related Security Bulletins