The safe_eval function in Ansible prior to 1.5.4 does not properly restrict the code subset, which allows remote malicious users to execute arbitrary code via crafted instructions.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
redhat ansible |