Ansible: vulnerability in solaris_zone module via crafted solaris zone
Published Aug 25, 2020
8.3
HIGHCVSS 4.0
EPSS 0.42%
Description
A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the remote machine. An attacker could take advantage of this flaw by crafting the name of the zone and executing arbitrary commands in the remote host. Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected.
Affected products
- Vendor n/a Product Ansible Defaultn/a
- Version All versions before ansible-engine 2.9.4, before ansible-engine 2.8.8 and before ansible-engine 2.7.16StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Ansible | n/a |
|
Configuration 1
Configuration 2
- 9.0
- 10.0
No data.
Red Hat Ansible Engine 2 for RHEL 7
ansible-0:2.9.4-1.el7ae
Fixed · RHSA-2020:0218
Red Hat Ansible Engine 2 for RHEL 8
ansible-0:2.9.4-1.el8ae
Fixed · RHSA-2020:0218
Red Hat Ansible Engine 2.7 for RHEL 7
ansible-0:2.7.16-1.el7ae
Fixed · RHSA-2020:0217
Red Hat Ansible Engine 2.8 for RHEL 7
ansible-0:2.8.8-1.el7ae
Fixed · RHSA-2020:0216
Red Hat Ansible Engine 2.8 for RHEL 8
ansible-0:2.8.8-1.el8ae
Fixed · RHSA-2020:0216
Red Hat Ansible Engine 2.9 for RHEL 7
ansible-0:2.9.4-1.el7ae
Fixed · RHSA-2020:0215
Red Hat Ansible Engine 2.9 for RHEL 8
ansible-0:2.9.4-1.el8ae
Fixed · RHSA-2020:0215
CloudForms Management Engine 5
ansible
Not affected
Red Hat Ansible Tower 3
ansible
Affected
Red Hat Ceph Storage 2
ansible
Out of support scope
Red Hat Ceph Storage 3
ansible
Out of support scope
Red Hat OpenStack Platform 10 (Newton)
ansible
Out of support scope
Red Hat OpenStack Platform 13 (Queens)
ansible
Out of support scope
Red Hat OpenStack Platform 14 (Rocky)
ansible
Out of support scope
Red Hat Storage 3
ansible
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Engine 2 for RHEL 7 | ansible-0:2.9.4-1.el7ae | Fixed | RHSA-2020:0218 |
| Red Hat Ansible Engine 2 for RHEL 8 | ansible-0:2.9.4-1.el8ae | Fixed | RHSA-2020:0218 |
| Red Hat Ansible Engine 2.7 for RHEL 7 | ansible-0:2.7.16-1.el7ae | Fixed | RHSA-2020:0217 |
| Red Hat Ansible Engine 2.8 for RHEL 7 | ansible-0:2.8.8-1.el7ae | Fixed | RHSA-2020:0216 |
| Red Hat Ansible Engine 2.8 for RHEL 8 | ansible-0:2.8.8-1.el8ae | Fixed | RHSA-2020:0216 |
| Red Hat Ansible Engine 2.9 for RHEL 7 | ansible-0:2.9.4-1.el7ae | Fixed | RHSA-2020:0215 |
| Red Hat Ansible Engine 2.9 for RHEL 8 | ansible-0:2.9.4-1.el8ae | Fixed | RHSA-2020:0215 |
| CloudForms Management Engine 5 | ansible | Not affected | n/a |
| Red Hat Ansible Tower 3 | ansible | Affected | n/a |
| Red Hat Ceph Storage 2 | ansible | Out of support scope | n/a |
| Red Hat Ceph Storage 3 | ansible | Out of support scope | n/a |
| Red Hat OpenStack Platform 10 (Newton) | ansible | Out of support scope | n/a |
| Red Hat OpenStack Platform 13 (Queens) | ansible | Out of support scope | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | ansible | Out of support scope | n/a |
| Red Hat Storage 3 | ansible | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Because a flaw exploit would depend on the use of Solaris and Red Hat does not support RHOSP on Solaris, the RHOSP Ansible package will not be updated at this time. Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected.
Red Hat mitigation
Currently, there is no mitigation for this issue.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L
AV:L/AC:L/Au:N/C:C/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.42% (0.00421) | 34.13th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.42% (0.00421) | 36.08th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.05% (0.00046) | 16.54th | v3 (v2023.03.01) |
| May 1, 2024 | 0.05% (0.00046) | 14.86th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00046) | 12.86th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00950) | 32.28th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.67% (0.01669) | 53.27th | v2 (v2022.01.01) |
| Feb 3, 2022 | 4.50% (0.04504) | 76.47th | v1 |
| Jan 6, 2022 | 4.50% (0.04504) | 76.26th | v1 |
| Oct 11, 2021 | 1.04% (0.01040) | 64.87th | v1 |
| Oct 10, 2021 | 4.50% (0.04504) | 84.10th | v1 |
| Aug 8, 2021 | 4.50% (0.04504) | 0.00th | v1 |
| Aug 7, 2021 | 0.83% (0.00833) | 0.00th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.83% (0.00833) | 0.00th | v1 |
References (12)
- https://access.redhat.com/security/cve/CVE-2019-14904 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1776944 x_refsource_MISCIssue TrackingVendor Advisory
- https://github.com/advisories/GHSA-gwr8-5j83-483c Advisory
- https://github.com/ansible/ansible/commit/589a415f887b6f2bb65cd07fe6b2e9d0a8156b69
- https://github.com/ansible/ansible/commit/6a86650109b8654f5898369e45d3857624edf907
- https://github.com/ansible/ansible/commit/a1b0f72c98b4b2afaab8aafa255e82c2075049c8
- https://github.com/ansible/ansible/pull/65686 x_refsource_MISCPatchThird Party Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2020-161.yaml
- https://lists.debian.org/debian-lts-announce/2021/01/msg00023.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-14904
- https://www.cve.org/CVERecord?id=CVE-2019-14904
- https://www.debian.org/security/2021/dsa-4950 vendor-advisoryx_refsource_DEBIANThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-14904 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1776944 | x_refsource_MISCIssue TrackingVendor Advisory | |
| https://github.com/advisories/GHSA-gwr8-5j83-483c | Advisory | |
| https://github.com/ansible/ansible/commit/589a415f887b6f2bb65cd07fe6b2e9d0a8156b69 | ||
| https://github.com/ansible/ansible/commit/6a86650109b8654f5898369e45d3857624edf907 | ||
| https://github.com/ansible/ansible/commit/a1b0f72c98b4b2afaab8aafa255e82c2075049c8 | ||
| https://github.com/ansible/ansible/pull/65686 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2020-161.yaml | ||
| https://lists.debian.org/debian-lts-announce/2021/01/msg00023.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-14904 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-14904 | ||
| https://www.debian.org/security/2021/dsa-4950 | vendor-advisoryx_refsource_DEBIANThird Party Advisory |
Change history (0)
No recorded changes yet.