Total vulnerabilities in the database
In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.
Software | From | Fixed in |
---|---|---|
redhat / virtualization_host | 4.0 | 4.0.x |
redhat / virtualization | 4.0 | 4.0.x |
redhat / ansible_engine | 2.5 | 2.5.x |
redhat / ansible_engine | 2.0 | 2.0.x |
redhat / ansible_engine | 2.4 | 2.4.x |
redhat / ansible_engine | 2.6 | 2.6.x |
redhat / openstack | 10 | 10.x |
redhat / openstack | 12 | 12.x |
redhat / openstack | 13 | 13.x |
![]() |
- | 2.5.6 |