Back

HIGH

ansible: Improper verification of key fingerprints in apt_key module

Published Jul 31, 2018

Description

A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 31, 2018
Updated Aug 6, 2024
Reserved Oct 12, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 1, 2016
GHSA-CMWX-9M2H-X7V4