ansible: safe_eval function does not properly restrict the code subset leads to arbitrary code execution via crafted instructions
Published Feb 20, 2020
9.3
CRITICALCVSS 4.0
EPSS 5.24%
Description
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.
Affected products
- Vendor n/a Product Ansible Defaultn/a
- Version before 1.6.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Ansible | n/a |
|
Configuration 2
- 8.0
- 9.0
- 10.0
No data.
CloudForms Management Engine 5
ansible
Not affected
Red Hat Ansible Engine 2
ansible
Not affected
Red Hat Ansible Tower 3
ansible
Not affected
Red Hat Ceph Storage 2
ansible
Not affected
Red Hat Ceph Storage 3
ansible
Not affected
Red Hat OpenStack Platform 10 (Newton)
ansible
Not affected
Red Hat OpenStack Platform 13 (Queens)
ansible
Not affected
Red Hat Storage 3
ansible
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5 | ansible | Not affected | n/a |
| Red Hat Ansible Engine 2 | ansible | Not affected | n/a |
| Red Hat Ansible Tower 3 | ansible | Not affected | n/a |
| Red Hat Ceph Storage 2 | ansible | Not affected | n/a |
| Red Hat Ceph Storage 3 | ansible | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | ansible | Not affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | ansible | Not affected | n/a |
| Red Hat Storage 3 | ansible | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Ceph Storage and Red Hat Gluster Storage shipped ansible versions 2.4.1 and 2.3.2 respectively, which are not affected by this vulnerability.
References (13)
- https://access.redhat.com/security/cve/CVE-2014-4678 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1828684 Issue Tracking
- https://github.com/advisories/GHSA-66c7-5pwv-mm3j Advisory
- https://github.com/ansible/ansible/commit/5429b85b9f6c2e640074176f36ff05fd5e4d1916 x_refsource_MISCPatchThird Party Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2020-203.yaml
- https://groups.google.com/forum/message/raw?msg=ansible-announce/ieV1vZvcTXU/5Q93ThkY9rIJ x_refsource_MISCThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-4678
- https://security-tracker.debian.org/tracker/CVE-2014-4678 x_refsource_MISCThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2014-4678
- https://www.openwall.com/lists/oss-security/2014/06/26/30 x_refsource_MISCMailing ListPatchThird Party Advisory
- https://www.openwall.com/lists/oss-security/2014/07/02/2 x_refsource_MISCMailing ListPatchThird Party Advisory
- https://www.rapid7.com/db/vulnerabilities/freebsd-vid-2c493ac8-205e-11e5-a4a5-002590263bf5 x_refsource_MISCThird Party Advisory
- https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2014-4678 x_refsource_MISCThird Party Advisory
Change history (0)
No recorded changes yet.