CVE-2016-8614
Summary
| CVE | CVE-2016-8614 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-31 21:29:00 UTC |
| Updated | 2023-11-07 02:36:00 UTC |
| Description | A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key. |
Risk And Classification
Problem Types: CWE-320
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security] apt_key module does not verify key fingerprints · Issue #5237 · ansible/ansible-modules-core · GitHub | CONFIRM | github.com | Exploit, Third Party Advisory |
| Order of return values was reversed by abadger · Pull Request #5357 · ansible/ansible-modules-core · GitHub | CONFIRM | github.com | Third Party Advisory |
| Only change to short IDs for delete by abadger · Pull Request #5353 · ansible/ansible-modules-core · GitHub | CONFIRM | github.com | Third Party Advisory |
| 1388038 – (CVE-2016-8614) CVE-2016-8614 ansible: Improper verification of key fingerprints in apt_key module | CONFIRM | bugzilla.redhat.com | Exploit, Issue Tracking, Patch, Third Party Advisory |
| Ansible CVE-2016-8614 Security Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981124 Python (pip) Security Update for ansible (GHSA-cmwx-9m2h-x7v4)