ZeroHour

CVE-2018-10875

CVSS 3.1
7.8 high
EPSS
<1%p46
Published
()
Modified
Description

A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.

Vendors
redhatdebiansusecanonical
Products
ansible engine, ceph storage, gluster storage, openshift, openstack, virtualization, virtualization host, debian linux, package hub, ubuntu linux
Weakness
CWE-426
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.