Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22777
HistoryMar 25, 2020 - 3:13 a.m.

Code Injection

2020-03-2503:13:26
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.0004 Low

EPSS

Percentile

14.2%

ansible is vulnerable to code injection. The ansible_facts subkey can be used to overwrite itself after cleaning when inject is enabled, allowing an attacker to modify values such as ansible_hosts, users or other key data which can potentially lead to code injection or privilege escalation.