Ansible: malicious code could craft filename in nxos_file_copy module
Published Mar 31, 2020
7.0
HIGHCVSS 4.0
EPSS 0.71%
Description
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.
Affected products
-
- Version 2.7.x and earlierStatusaffectedConstraints-
- Version 2.7.x before 2.7.16StatusaffectedConstraints-
- Version 2.8.x before 2.8.8StatusaffectedConstraints-
- Version 2.9.x before 2.9.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Configuration 1
- ≥ 2.7.0 · < 2.7.16
- ≥ 2.8.0 · < 2.8.8
- ≥ 2.9.0 · < 2.9.3
Configuration 2
- 3.0.0
- 3.0
- 5.0
- 13
Configuration 3
- 30
Configuration 4
- 15.0
- 15.1
No data.
Red Hat Ansible Engine 2 for RHEL 7
ansible-0:2.9.4-1.el7ae
Fixed · RHSA-2020:0218
Red Hat Ansible Engine 2 for RHEL 8
ansible-0:2.9.4-1.el8ae
Fixed · RHSA-2020:0218
Red Hat Ansible Engine 2.7 for RHEL 7
ansible-0:2.7.16-1.el7ae
Fixed · RHSA-2020:0217
Red Hat Ansible Engine 2.8 for RHEL 7
ansible-0:2.8.8-1.el7ae
Fixed · RHSA-2020:0216
Red Hat Ansible Engine 2.8 for RHEL 8
ansible-0:2.8.8-1.el8ae
Fixed · RHSA-2020:0216
Red Hat Ansible Engine 2.9 for RHEL 7
ansible-0:2.9.4-1.el7ae
Fixed · RHSA-2020:0215
Red Hat Ansible Engine 2.9 for RHEL 8
ansible-0:2.9.4-1.el8ae
Fixed · RHSA-2020:0215
CloudForms Management Engine 5
ansible
Not affected
Red Hat Ansible Tower 3
ansible
Affected
Red Hat Ceph Storage 2
ansible
Out of support scope
Red Hat Ceph Storage 3
ansible
Will not fix
Red Hat OpenStack Platform 10 (Newton)
ansible
Out of support scope
Red Hat OpenStack Platform 13 (Queens)
ansible
Will not fix
Red Hat OpenStack Platform 14 (Rocky)
ansible
Out of support scope
Red Hat Storage 3
ansible
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Engine 2 for RHEL 7 | ansible-0:2.9.4-1.el7ae | Fixed | RHSA-2020:0218 |
| Red Hat Ansible Engine 2 for RHEL 8 | ansible-0:2.9.4-1.el8ae | Fixed | RHSA-2020:0218 |
| Red Hat Ansible Engine 2.7 for RHEL 7 | ansible-0:2.7.16-1.el7ae | Fixed | RHSA-2020:0217 |
| Red Hat Ansible Engine 2.8 for RHEL 7 | ansible-0:2.8.8-1.el7ae | Fixed | RHSA-2020:0216 |
| Red Hat Ansible Engine 2.8 for RHEL 8 | ansible-0:2.8.8-1.el8ae | Fixed | RHSA-2020:0216 |
| Red Hat Ansible Engine 2.9 for RHEL 7 | ansible-0:2.9.4-1.el7ae | Fixed | RHSA-2020:0215 |
| Red Hat Ansible Engine 2.9 for RHEL 8 | ansible-0:2.9.4-1.el8ae | Fixed | RHSA-2020:0215 |
| CloudForms Management Engine 5 | ansible | Not affected | n/a |
| Red Hat Ansible Tower 3 | ansible | Affected | n/a |
| Red Hat Ceph Storage 2 | ansible | Out of support scope | n/a |
| Red Hat Ceph Storage 3 | ansible | Will not fix | n/a |
| Red Hat OpenStack Platform 10 (Newton) | ansible | Out of support scope | n/a |
| Red Hat OpenStack Platform 13 (Queens) | ansible | Will not fix | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | ansible | Out of support scope | n/a |
| Red Hat Storage 3 | ansible | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected. Red Hat Gluster Storage 3 and Red Hat Ceph Storage 3 no longer maintain their own version of Ansible. Therefore this fix will be consumed directly from core Ansible. In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP ansible package.
Red Hat mitigation
There is no mitigation for this issue, the flaw can only be resolved by applying updates.
References (14)
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0216 vendor-advisoryx_refsource_REDHATPatchVendor Advisory
- https://access.redhat.com/errata/RHSA-2020:0218 vendor-advisoryx_refsource_REDHATPatchVendor Advisory
- https://access.redhat.com/security/cve/CVE-2019-14905 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1776943 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14905 x_refsource_CONFIRMIssue TrackingPatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0018 Advisory
- https://github.com/advisories/GHSA-frxj-5j27-f8rf Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2020-206.yaml
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5BNCYPQ4BY5QHBCJOAOPANB5FHATW2BR/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5BNCYPQ4BY5QHBCJOAOPANB5FHATW2BR
- https://nvd.nist.gov/vuln/detail/CVE-2019-14905
- https://www.cve.org/CVERecord?id=CVE-2019-14905
Change history (0)
No recorded changes yet.