QID 997077
Date Published: 2024-02-02
QID 997077: Python (Pip) Security Update for ansible (GHSA-64cw-m57j-65xj)
Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansible managed host and providing a crafted fact, as demonstrated by a fact with (1) a trailing " src=" clause, (2) a trailing " temp=" clause, or (3) a trailing " validate=" clause accompanied by a shell command.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-64cw-m57j-65xj for updates and patch information.
Vendor References
- GHSA-64cw-m57j-65xj -
github.com/advisories/GHSA-64cw-m57j-65xj
CVEs related to QID 997077
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-64cw-m57j-65xj | ansible |
|