Lucene search

K
osvGoogleOSV:CVE-2018-10874
HistoryJul 02, 2018 - 1:29 p.m.

CVE-2018-10874

2018-07-0213:29:00
Google
osv.dev
11

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

32.4%

In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker’s control, allowing to run arbitrary code as a result.