Back

CRITICAL

ansible: safe_eval function does not properly restrict the code subset leads to arbitrary code execution via crafted instructions

Published Feb 20, 2020

Description

The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.

Affected products

Remediation

Red Hat statement

Red Hat Ceph Storage and Red Hat Gluster Storage shipped ansible versions 2.4.1 and 2.3.2 respectively, which are not affected by this vulnerability.

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 20, 2020
Updated Aug 6, 2024
Reserved Jun 26, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 19, 2020
GHSA-66C7-5PWV-MM3J