Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4222
HistoryMay 11, 2017 - 5:59 a.m.

Arbitrary Code Execution

2017-05-1105:59:26
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.014 Low

EPSS

Percentile

86.3%

ansible is vulnerable to arbitrary code execution. The attacks are possible because it does not strip lookup calls out of inventory variables and clean unsafe data returned from lookup plugins. The code execution can be performed by interpolating file names as lookup plugin commands in combination with the pipe feature.

CPENameOperatorVersion
ansiblele1.6.6