0.001 Low
EPSS
Percentile
33.7%
It was found that ansible.cfg is being read from the current working directory, which can be made to point to plugin or module paths that are under control of the attacker. This could allow an attacker to execute arbitrary code.
bugzilla.redhat.com/show_bug.cgi?id=1596533
www.cve.org/CVERecord?id=CVE-2018-10875 https://nvd.nist.gov/vuln/detail/CVE-2018-10875