QID 980236
QID 980236: Python (pip) Security Update for ansible (GHSA-frxj-5j27-f8rf)
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-frxj-5j27-f8rf for updates pertaining to this vulnerability.
Vendor References
- GHSA-frxj-5j27-f8rf -
github.com/advisories/GHSA-frxj-5j27-f8rf
CVEs related to QID 980236
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-frxj-5j27-f8rf | ansible |
|