HIGH
ansible: multiple issues fixed in 1.9.2
Published Jun 7, 2017
8.5
HIGHCVSS 4.0
EPSS 0.45%
Description
The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environment via a symlink attack.
Affected products
No data.
No data.
Red Hat OpenShift Enterprise 3
ansible
Not affected
Red Hat OpenStack Platform 10 (Newton)
ansible
Not affected
Red Hat Quickstart Cloud Installer 1
ansible
Not affected
Red Hat Storage 3
ansible
Not affected
Red Hat Storage Console 2
ansible
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Enterprise 3 | ansible | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | ansible | Not affected | n/a |
| Red Hat Quickstart Cloud Installer 1 | ansible | Not affected | n/a |
| Red Hat Storage 3 | ansible | Not affected | n/a |
| Red Hat Storage Console 2 | ansible | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- http://www.ansible.com/security
- http://www.openwall.com/lists/oss-security/2015/08/17/10 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2015-6240 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1243468 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://github.com/advisories/GHSA-wwwh-47wp-m522 Advisory
- https://github.com/ansible/ansible/commit/952166f48eb0f5797b75b160fd156bbe1e8fc647 x_refsource_CONFIRMPatch
- https://github.com/ansible/ansible/commit/ca2f2c4ebd7b5e097eab0a710f79c1f63badf95b x_refsource_CONFIRMPatch
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2017-3.yaml
- https://lists.debian.org/debian-lts-announce/2019/09/msg00016.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2015-6240
- https://www.cve.org/CVERecord?id=CVE-2015-6240
| Link | Providers | Tags |
|---|---|---|
| http://www.ansible.com/security | ||
| http://www.openwall.com/lists/oss-security/2015/08/17/10 | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2015-6240 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1243468 | x_refsource_CONFIRMIssue TrackingThird Party Advisory | |
| https://github.com/advisories/GHSA-wwwh-47wp-m522 | Advisory | |
| https://github.com/ansible/ansible/commit/952166f48eb0f5797b75b160fd156bbe1e8fc647 | x_refsource_CONFIRMPatch | |
| https://github.com/ansible/ansible/commit/ca2f2c4ebd7b5e097eab0a710f79c1f63badf95b | x_refsource_CONFIRMPatch | |
| https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2017-3.yaml | ||
| https://lists.debian.org/debian-lts-announce/2019/09/msg00016.html | mailing-listx_refsource_MLIST | |
| https://nvd.nist.gov/vuln/detail/CVE-2015-6240 | ||
| https://www.cve.org/CVERecord?id=CVE-2015-6240 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 7, 2017
Updated Aug 6, 2024
Reserved Aug 14, 2015
Link CVE-2015-6240
CISA Vulnrichment
GHSA-WWWH-47WP-M522 Updated n/a