QID 981142
QID 981142: Python (pip) Security Update for ansible (GHSA-c2w9-48qc-qpj4)
An exploitable vulnerability exists in the yaml loading functionality of ansible-vault before 1.0.5. A specially crafted vault can execute arbitrary python commands resulting in command execution. An attacker can insert python into the vault to trigger this vulnerability.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-c2w9-48qc-qpj4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-c2w9-48qc-qpj4 -
github.com/advisories/GHSA-c2w9-48qc-qpj4
CVEs related to QID 981142
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c2w9-48qc-qpj4 | ansible |
|