Command Injection in Ansible - CVE-2016-8628

 

Command Injection in Ansible - CVE-2016-8628

Published: July 31, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU36808
CSH Severity: High
CVSS v4: 6.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H]
CVE-ID: CVE-2016-8628
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote privileged user to execute arbitrary code.

Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the user Ansible runs as.


Affected software

Ansible
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Manager Retail Branch Server
SUSE Manager Proxy Module
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Manager Client Tools for SLE Micro
Fedora
SUSE Manager Client Tools for SLE
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Package Hub 15
openSUSE Leap
Red Hat OpenShift Container Platform
POS_Image-JeOS7
POS_Image-Graphical7
dracut-saltboot
golang-github-prometheus-promu
ansible (Red Hat package)
ansible
ansible-doc
ansible-test
openshift-ansible (Red Hat package)
spacewalk-koan
python3-spacewalk-koan
mgr-daemon
python3-uyuni-common-libs
uyuni-proxy-systemd-services
spacewalk-check
python3-spacewalk-client-tools
python3-spacewalk-check
spacewalk-client-setup
spacewalk-client-tools
python3-spacewalk-client-setup
spacecmd
grafana-debuginfo
grafana

How to mitigate CVE-2016-8628

Install update from vendor's website.

Ansible - update to 2.2.0
POS_Image-JeOS7 - update to 0.1.1710765237.46af599-150000.1.21.2
POS_Image-Graphical7 - update to 0.1.1710765237.46af599-150000.1.21.2
dracut-saltboot - update to 0.1.1710765237.46af599-150000.1.53.2
golang-github-prometheus-promu - update to 0.14.0-150000.3.18.2
ansible (Red Hat package) - update to 2.2.0.0-1.el7
ansible - addressed in versions 2.2.0.0-2.el6, 2.2.0.0-2.el7, 2.2.0.0-2.fc24, 2.2.0.0-2.fc25, 2.2.0.0-3.el6, 2.2.0.0-3.el7, 2.2.0.0-3.fc24, 2.2.0.0-3.fc25
ansible-doc - update to 2.9.27-150000.1.17.2
ansible-test - update to 2.9.27-150000.1.17.2
ansible - update to 2.9.27-150000.1.17.2
openshift-ansible (Red Hat package) - addressed in versions 3.2.42-1.git.0.6b09be9.el7, 3.3.50-1.git.0.5bdbeaa.el7
spacewalk-koan - update to 4.3.6-150000.3.33.2
python3-spacewalk-koan - update to 4.3.6-150000.3.33.2
mgr-daemon - update to 4.3.9-150000.1.47.2
python3-uyuni-common-libs - update to 4.3.10-150000.1.39.2
uyuni-proxy-systemd-services - update to 4.3.12-150000.1.21.2
spacewalk-check - update to 4.3.19-150000.3.89.2
python3-spacewalk-client-tools - update to 4.3.19-150000.3.89.2
python3-spacewalk-check - update to 4.3.19-150000.3.89.2
spacewalk-client-setup - update to 4.3.19-150000.3.89.2
spacewalk-client-tools - update to 4.3.19-150000.3.89.2
python3-spacewalk-client-setup - update to 4.3.19-150000.3.89.2
spacecmd - update to 4.3.27-150000.3.116.2
grafana-debuginfo - update to 9.5.18-150000.1.63.2
grafana - update to 9.5.18-150000.1.63.2

External References

Related Security Bulletins