{"api_version":"1","generated_at":"2026-07-23T03:48:05+00:00","cve":"CVE-2016-8614","urls":{"html":"https://cve.report/CVE-2016-8614","api":"https://cve.report/api/cve/CVE-2016-8614.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-8614","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-8614"},"summary":{"title":"CVE-2016-8614","description":"A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2018-07-31 21:29:00","updated_at":"2023-11-07 02:36:00"},"problem_types":["CWE-320"],"metrics":[],"references":[{"url":"https://github.com/ansible/ansible-modules-core/issues/5237","name":"https://github.com/ansible/ansible-modules-core/issues/5237","refsource":"CONFIRM","tags":["Exploit","Third Party Advisory"],"title":"[security] apt_key module does not verify key fingerprints · Issue #5237 · ansible/ansible-modules-core · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/ansible/ansible-modules-core/pull/5357","name":"https://github.com/ansible/ansible-modules-core/pull/5357","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"Order of return values was reversed by abadger · Pull Request #5357 · ansible/ansible-modules-core · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/ansible/ansible-modules-core/pull/5353","name":"https://github.com/ansible/ansible-modules-core/pull/5353","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"Only change to short IDs for delete by abadger · Pull Request #5353 · ansible/ansible-modules-core · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8614","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8614","refsource":"CONFIRM","tags":["Exploit","Issue Tracking","Patch","Third Party Advisory"],"title":"1388038 – (CVE-2016-8614) CVE-2016-8614 ansible: Improper verification of key fingerprints in apt_key module","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/94108","name":"94108","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Ansible CVE-2016-8614 Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-8614","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-8614","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"8614","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"ansible","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"8614","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"ansible","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2016-8614","qid":"981124","title":"Python (pip) Security Update for ansible (GHSA-cmwx-9m2h-x7v4)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2016-8614","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Ansible","version":{"version_data":[{"version_value":"2.2.0"}]}}]},"vendor_name":"Red Hat"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key."}]},"impact":{"cvss":[[{"vectorString":"6.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","version":"3.0"}],[{"vectorString":"6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P","version":"2.0"}]]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-358"}]}]},"references":{"reference_data":[{"name":"94108","refsource":"BID","url":"http://www.securityfocus.com/bid/94108"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8614","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8614"},{"name":"https://github.com/ansible/ansible-modules-core/pull/5353","refsource":"CONFIRM","url":"https://github.com/ansible/ansible-modules-core/pull/5353"},{"name":"https://github.com/ansible/ansible-modules-core/pull/5357","refsource":"CONFIRM","url":"https://github.com/ansible/ansible-modules-core/pull/5357"},{"name":"https://github.com/ansible/ansible-modules-core/issues/5237","refsource":"CONFIRM","url":"https://github.com/ansible/ansible-modules-core/issues/5237"}]}},"nvd":{"publishedDate":"2018-07-31 21:29:00","lastModifiedDate":"2023-11-07 02:36:00","problem_types":["CWE-320"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*","versionEndExcluding":"2.2.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"8614","Ordinal":"95269","Title":"CVE-2016-8614","CVE":"CVE-2016-8614","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"8614","Ordinal":"1","NoteData":"A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.","Type":"Description","Title":null},{"CveYear":"2016","CveId":"8614","Ordinal":"2","NoteData":"2018-07-31","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"8614","Ordinal":"3","NoteData":"2018-08-01","Type":"Other","Title":"Modified"}]}}}