Back

HIGH

ansible: Inventory variables are loaded from current working directory when running ad-hoc command that can lead to code execution

Published Jul 2, 2018

Description

In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.

Affected products

Remediation

Red Hat statement

Red Hat Gluster Storage 3 and Red Hat Ceph Storage 3 ships the affected version of ansible, but they no longer maintain their own version of ansible. Both the products will consume fixes directly from ansible repository.

Metrics

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 2, 2018
Updated Aug 5, 2024
Reserved May 9, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 29, 2018
GHSA-3XVG-X47J-X75W