Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22053
HistoryNov 29, 2019 - 6:23 a.m.

OS Command Injection

2019-11-2906:23:27
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.0005 Low

EPSS

Percentile

17.9%

Ansible is vulnerable to OS command injection. The attack is possible because the module nxos_file_copy does not validate the remote_file parameter and directly uses the filenames from the parameter to copy files to a flash or bootflash on NXOS devices, allowing an attacker to inject malicious command through it.