Back

HIGH

Ansible: malicious code could craft filename in nxos_file_copy module

Published Mar 31, 2020

Description

A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.

Affected products

Remediation

Red Hat statement

Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected. Red Hat Gluster Storage 3 and Red Hat Ceph Storage 3 no longer maintain their own version of Ansible. Therefore this fix will be consumed directly from core Ansible. In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP ansible package.

Red Hat mitigation

There is no mitigation for this issue, the flaw can only be resolved by applying updates.

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 31, 2020
Updated Aug 5, 2024
Reserved Aug 10, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 27, 2019
ENISA EUVD
Assigner redhat
Published Mar 31, 2020
Updated Aug 5, 2024
Exploited since n/a
EUVD-2020-0018 GHSA-FRXJ-5J27-F8RF