Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper...
Vulnerability Description
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-9587
Credits & Attribution
No credits recorded in the NVD database.
References
- https://access.redhat.com/errata/RHSA-2017:0515
- https://www.exploit-db.com/exploits/41013/
- https://security.gentoo.org/glsa/201701-77
- https://access.redhat.com/errata/RHSA-2017:1685
- http://www.securityfocus.com/bid/95352
- https://access.redhat.com/errata/RHSA-2017:0448
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9587
- http://rhn.redhat.com/errata/RHSA-2017-0195.html
- http://rhn.redhat.com/errata/RHSA-2017-0260.html
More from unspecified
View All →Affected Vendor
unspecified
View all reports →