CVE-2016-8628
Last modified
CVE-2016-8628 is a high-severity vulnerability rated 7.6/10 on the CVSS scale. Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the user Ansible runs as.. EPSS estimates a 3.25% chance of exploitation in the next 30 days.
Description
Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the user Ansible runs as.
Metrics
CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Ansible | < 2.2.0 |
References
- http://www.securityfocus.com/bid/94109Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2016:2778Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8628Issue Tracking, Third Party Advisory
- http://www.securityfocus.com/bid/94109Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2016:2778Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8628Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-8628?
How severe is CVE-2016-8628?
How do I fix CVE-2016-8628?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-8622The URL percent-encoding decode function in libcurl before 7…3.7
- CVE-2016-8623A flaw was found in curl before version 7.51.0. The way curl…3.3
- CVE-2016-8624curl before version 7.51.0 doesn't parse the authority compo…5.3
- CVE-2016-8625curl before version 7.51.0 uses outdated IDNA 2003 standard …5.3
- CVE-2016-8626A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ce…6.5
- CVE-2016-8627admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulner…4.3
- CVE-2016-8629Red Hat Keycloak before version 2.4.0 did not correctly chec…
- CVE-2016-8630The x86_decode_insn function in arch/x86/kvm/emulate.c in th…
- CVE-2016-8631The OpenShift Enterprise 3 router does not properly sort rou…6.3
- CVE-2016-8632The tipc_msg_build function in net/tipc/msg.c in the Linux k…7.8
- CVE-2016-8633drivers/firewire/net.c in the Linux kernel before 4.8.7, in …
- CVE-2016-8634A vulnerability was found in foreman 1.14.0. When creating a…6.1
Are you affected by CVE-2016-8628?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
