CVE-2019-14905
31.03.2020, 17:15
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | ansible_engine | 2.7.0 ≤ 𝑥 < 2.7.16 |
redhat | ansible_engine | 2.8.0 ≤ 𝑥 < 2.8.8 |
redhat | ansible_engine | 2.9.0 ≤ 𝑥 < 2.9.3 |
redhat | ansible_tower | 3.0.0 |
redhat | ceph_storage | 3.0 |
redhat | cloudforms_management_engine | 5.0 |
opensuse | backports_sle | 15.0:sp1 |
opensuse | leap | 15.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
- CWE-20 - Improper Input ValidationThe product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
- CWE-668 - Exposure of Resource to Wrong SphereThe product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
References