CVE-2016-8628
Last modified
CVE-2016-8628 is a vulnerability of currently unknown severity. Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the user Ansible runs as.. EPSS estimates a 3.25% chance of exploitation in the next 30 days.
Description
Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the user Ansible runs as.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Ansible | < 2.2.0 |
References
- http://www.securityfocus.com/bid/94109Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2016:2778Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8628Issue Tracking, Third Party Advisory
- http://www.securityfocus.com/bid/94109Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2016:2778Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8628Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-8628?
How severe is CVE-2016-8628?
How do I fix CVE-2016-8628?
Are you affected by CVE-2016-8628?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
