Lucene search

K
prionPRIOn knowledge basePRION:CVE-2014-4966
HistoryFeb 18, 2020 - 3:15 p.m.

Code injection

2020-02-1815:15:00
PRIOn knowledge base
www.prio-n.com
6

8.1 High

AI Score

Confidence

Low

0.014 Low

EPSS

Percentile

86.3%

Ansible before 1.6.7 does not prevent inventory data with “{{” and “lookup” substrings, and does not prevent remote data with “{{” substrings, which allows remote attackers to execute arbitrary code via (1) crafted lookup(‘pipe’) calls or (2) crafted Jinja2 data.

CPENameOperatorVersion
ansiblelt1.6.7

8.1 High

AI Score

Confidence

Low

0.014 Low

EPSS

Percentile

86.3%