CVE-2018-10875

HIGHCVSS 7.8/10EPSS 0.59%

Last modified

CVE-2018-10875 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.. EPSS estimates a 0.59% chance of exploitation in the next 30 days.

Description

A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.59%

43.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
RedhatAnsible Engine2.0
RedhatAnsible Engine2.4
RedhatAnsible Engine2.5
RedhatAnsible Engine2.6
RedhatCeph Storage2.0
RedhatCeph Storage3.0
RedhatGluster Storage3.0.0
RedhatOpenshift3.0
RedhatOpenstack10
RedhatOpenstack12
RedhatOpenstack13
RedhatVirtualization4.0
RedhatVirtualization Host4.0
DebianDebian Linux9.0
SusePackage HubAll versions
CanonicalUbuntu Linux16.04
CanonicalUbuntu Linux18.04
CanonicalUbuntu Linux19.04
DebianDebian Linux8.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-10875?
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.
How severe is CVE-2018-10875?
CVE-2018-10875 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.59% probability of exploitation in the next 30 days.
How do I fix CVE-2018-10875?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-10875?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST