CVE-2016-9587
Last modified
CVE-2016-9587 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.. EPSS estimates a 17.87% chance of exploitation in the next 30 days.
Description
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Ansible | < 2.1.4 |
| Ansible | Ansible | < 2.2.1 |
| Redhat | Openstack | 11 |
References
- http://rhn.redhat.com/errata/RHSA-2017-0195.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0260.htmlThird Party Advisory
- http://www.securityfocus.com/bid/95352Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:0448Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:0515Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1685Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9587Issue Tracking, Third Party Advisory
- https://security.gentoo.org/glsa/201701-77Third Party Advisory
- https://www.exploit-db.com/exploits/41013/Exploit, Third Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2017-0195.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0260.htmlThird Party Advisory
- http://www.securityfocus.com/bid/95352Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:0448Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:0515Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1685Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9587Issue Tracking, Third Party Advisory
- https://security.gentoo.org/glsa/201701-77Third Party Advisory
- https://www.exploit-db.com/exploits/41013/Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-9587?
How severe is CVE-2016-9587?
How do I fix CVE-2016-9587?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-9581An infinite loop vulnerability in tiftoimage that results in…3.3
- CVE-2016-9582Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2016-9583An out-of-bounds heap read vulnerability was found in the jp…5.5
- CVE-2016-9584libical allows remote attackers to cause a denial of service…
- CVE-2016-9585Red Hat JBoss EAP version 5 is vulnerable to a deserializati…
- CVE-2016-9586curl before version 7.52.0 is vulnerable to a buffer overflo…5.9
- CVE-2016-9588arch/x86/kvm/vmx.c in the Linux kernel through 4.9 mismanage…
- CVE-2016-9589Undertow in Red Hat wildfly before version 11.0.0.Beta1 is v…
- CVE-2016-9590puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to a…6.5
- CVE-2016-9591JasPer before version 2.0.12 is vulnerable to a use-after-fr…
- CVE-2016-9592openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnera…4.3
- CVE-2016-9593foreman-debug before version 1.15.0 is vulnerable to a flaw …4.7
Are you affected by CVE-2016-9587?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
