Ansible before version 2.3 has an input validation vulnerability in...
Vulnerability Description
Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a client system being managed by Ansible, and the ability to send facts back to the Ansible server, could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-7466
Credits & Attribution
No credits recorded in the NVD database.
References
- https://access.redhat.com/errata/RHSA-2017:1599
- https://access.redhat.com/errata/RHSA-2017:1334
- http://www.securityfocus.com/bid/97595
- https://access.redhat.com/errata/RHSA-2017:1685
- https://access.redhat.com/errata/RHSA-2017:1244
- https://access.redhat.com/errata/RHSA-2017:1499
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7466
- https://access.redhat.com/errata/RHSA-2017:1476
More from [UNKNOWN]
View All →Affected Vendor
[UNKNOWN]
View all reports →