4.3
CVSSv2

CVE-2015-3908

Published: 12/08/2015 Updated: 16/09/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Ansible prior to 1.9.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle malicious users to spoof SSL servers via an arbitrary valid certificate.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat ansible

Vendor Advisories

Ansible before 192 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate ...

Github Repositories

Ansible Changes By Release 21 TBD - ACTIVE DEVELOPMENT ####New Modules: cloudstack: cs_volume ####New Filters: extract 201 "Over the Hills and Far Away" Fixes a major compatibility break in the synchronize module shipped with 200x That version of synchronize ran sudo on the controller prior to running rsync In 19x and previous, sudo was run on the hos