Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22593
HistoryFeb 28, 2020 - 5:00 a.m.

Remote Code Execution (RCE)

2020-02-2805:00:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

0.0005 Low

EPSS

Percentile

17.4%

ansible is vulnerable to remote code execution. The vulnerability exists as the package and service modules allows the ansible_facts['pkg_mgr'] and ansible_facts['service_mgr'] facts to be set to a module name such as ansible_collections.namespace.name./tmp/reverse-shell, allowing remote code execution on the managed node.

CPENameOperatorVersion
ansiblele2.8.9
ansiblele2.7.16
ansiblele2.9.6