QID 981352
QID 981352: Python (pip) Security Update for ansible (GHSA-m956-frf4-m2wr)
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-m956-frf4-m2wr for updates pertaining to this vulnerability.
Vendor References
- GHSA-m956-frf4-m2wr -
github.com/advisories/GHSA-m956-frf4-m2wr
CVEs related to QID 981352
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-m956-frf4-m2wr | ansible |
|