Ansible Arbitrary Code Execution
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Sep 5, 2024
Package
Affected versions
< 2.4.6.0
>= 2.5.0a1, < 2.5.6
>= 2.6.0a1, < 2.6.1
Patched versions
2.4.6.0
2.5.6
2.6.1
Description
Published by the National Vulnerability Database
Jul 13, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Apr 22, 2024
Last updated
Sep 5, 2024
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.
References