7.5
CVSSv2

CVE-2014-4966

Published: 18/02/2020 Updated: 26/02/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Ansible prior to 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which allows remote malicious users to execute arbitrary code via (1) crafted lookup('pipe') calls or (2) crafted Jinja2 data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat ansible

Github Repositories

Ansible Changes By Release 21 TBD - ACTIVE DEVELOPMENT ####New Modules: cloudstack: cs_volume ####New Filters: extract 201 "Over the Hills and Far Away" Fixes a major compatibility break in the synchronize module shipped with 200x That version of synchronize ran sudo on the controller prior to running rsync In 19x and previous, sudo was run on the hos