QID 375885

Date Published: 2021-09-29

QID 375885: Ansible Engine Arbitrary Code Execution Vulnerability

Ansible is an open-source community project sponsored by Red Hat, it's the simplest way to automate IT.

Affected Versions:
Prior to 2.8.15
prior to 2.9.13

QID Detection Logic(Authenticated):
This QID checks for vulnerable versions of ansible.

A successful exploit could allow the attacker to execute arbitrary code and completely compromise the system.

  • CVSS V3 rated as High - 7.1 severity.
  • CVSS V2 rated as High - 6.6 severity.
  • Solution
    Customers are advised to download the latest version of ansible 2.8.16 or 2.9.14
    For more information, visit ansible-2-9-14ansible-2-8-16

    CVEs related to QID 375885

    Software Advisories
    Advisory ID Software Component Link
    ansible-2-8-16 URL Logo github.com/ansible/ansible/blob/stable-2.8/changelogs/CHANGELOG-v2.8.rst#v2-8-16
    ansible-2-9-14 URL Logo github.com/ansible/ansible/blob/stable-2.9/changelogs/CHANGELOG-v2.9.rst#v2-9-14