QID 980817
QID 980817: Python (pip) Security Update for ansible (GHSA-w64c-pxjj-h866)
Ansible before 1.9.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-w64c-pxjj-h866 for updates pertaining to this vulnerability.
Vendor References
- GHSA-w64c-pxjj-h866 -
github.com/advisories/GHSA-w64c-pxjj-h866
CVEs related to QID 980817
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-w64c-pxjj-h866 | ansible |
|