8
CVSSv3

CVE-2017-7466

Published: 22/06/2018 Updated: 04/08/2021
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
CVSS v3 Base Score: 8 | Impact Score: 5.9 | Exploitability Score: 2.1
VMScore: 756
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a client system being managed by Ansible, and the ability to send facts back to the Ansible server, could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat ansible

redhat openstack 11

redhat openstack 10

Vendor Advisories

Synopsis Important: ansible security update Type/Severity Security Advisory: Important Topic An update for ansible is now available for Red Hat Gluster Storage 32 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability S ...
Synopsis Important: ansible security update Type/Severity Security Advisory: Important Topic An update for ansible is now available for Red Hat OpenStack Platform 100 (Newton)Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVS ...
Synopsis Important: ansible security update Type/Severity Security Advisory: Important Topic An update for ansible is now available for Red Hat OpenStack Platform 110 (Ocata)Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS ...
Synopsis Important: ansible security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An update for ansible is now available for RHEV Engine version 41Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring Sy ...
Synopsis Important: ansible security update Type/Severity Security Advisory: Important Topic An update for ansible is now available for Red Hat Storage Console 2 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Sco ...
Synopsis Important: ansible and openshift-ansible security and bug fix update Type/Severity Security Advisory: Important Topic An update for ansible and openshift-ansible is now available for Red Hat OpenShift Container Platform 32, Red Hat OpenShift Container Platform 33, Red Hat OpenShift Container Plat ...
An input validation vulnerability was found in Ansible's handling of data sent from client systems An attacker with control over a client system being managed by Ansible, and the ability to send facts back to the Ansible server, could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges ...