CVE-2018-10875
13.07.2018, 22:29
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | ansible_engine | 2.0 |
redhat | ansible_engine | 2.4 |
redhat | ansible_engine | 2.5 |
redhat | ansible_engine | 2.6 |
redhat | ceph_storage | 2.0 |
redhat | ceph_storage | 3.0 |
redhat | gluster_storage | 3.0.0 |
redhat | openshift | 3.0 |
redhat | virtualization | 4.0 |
redhat | virtualization_host | 4.0 |
debian | debian_linux | 9.0 |
suse | package_hub | - |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 19.04 |
debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ansible |
|
Common Weakness Enumeration
References