CVE-2016-9587
Ansible 2.1.4/2.2.1 - Command Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.
Ansible, en versiones anteriores a la 2.1.4 y la 2.2.1, es vulnerable a una validación de entradas incorrecta en la gestión de Ansible de datos enviados desde los sistemas de clientes. Un atacante que tenga el control de un sistema de cliente gestionado por Ansible y la capacidad de enviar hechos de vuelta al servidor de Ansible podría usar este error para ejecutar código arbitrario en el servidor de Ansible utilizando los privilegios del servidor de Ansible.
An input validation vulnerability was found in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-11-23 CVE Reserved
- 2017-01-12 CVE Published
- 2024-07-28 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/95352 | Third Party Advisory | |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9587 | Issue Tracking |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/41013 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2017-0195.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2017-0260.html | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2017:0448 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2017:0515 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2017:1685 | 2023-11-07 | |
https://security.gentoo.org/glsa/201701-77 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2016-9587 | 2017-07-06 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1404378 | 2017-07-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Ansible Search vendor "Redhat" for product "Ansible" | < 2.1.4 Search vendor "Redhat" for product "Ansible" and version " < 2.1.4" | - |
Affected
| ||||||
Ansible Search vendor "Ansible" | Ansible Search vendor "Ansible" for product "Ansible" | < 2.2.1 Search vendor "Ansible" for product "Ansible" and version " < 2.2.1" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openstack Search vendor "Redhat" for product "Openstack" | 11 Search vendor "Redhat" for product "Openstack" and version "11" | - |
Affected
|