QID 981124
QID 981124: Python (pip) Security Update for ansible (GHSA-cmwx-9m2h-x7v4)
A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cmwx-9m2h-x7v4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-cmwx-9m2h-x7v4 -
github.com/advisories/GHSA-cmwx-9m2h-x7v4
CVEs related to QID 981124
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cmwx-9m2h-x7v4 | ansible |
|