CVE-2016-9587
Last modified
CVE-2016-9587 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.. EPSS estimates a 17.87% chance of exploitation in the next 30 days.
Description
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Ansible | < 2.1.4 |
| Ansible | Ansible | < 2.2.1 |
| Redhat | Openstack | 11 |
References
- http://rhn.redhat.com/errata/RHSA-2017-0195.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0260.htmlThird Party Advisory
- http://www.securityfocus.com/bid/95352Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:0448Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:0515Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1685Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9587Issue Tracking, Third Party Advisory
- https://security.gentoo.org/glsa/201701-77Third Party Advisory
- https://www.exploit-db.com/exploits/41013/Exploit, Third Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2017-0195.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0260.htmlThird Party Advisory
- http://www.securityfocus.com/bid/95352Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:0448Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:0515Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1685Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9587Issue Tracking, Third Party Advisory
- https://security.gentoo.org/glsa/201701-77Third Party Advisory
- https://www.exploit-db.com/exploits/41013/Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-9587?
How severe is CVE-2016-9587?
How do I fix CVE-2016-9587?
Are you affected by CVE-2016-9587?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
