Argument Injection in Ansible
Low severity
GitHub Reviewed
Published
Feb 9, 2022
to the GitHub Advisory Database
•
Updated Sep 6, 2024
Package
Affected versions
>= 0, <= 2.7.16
>= 2.8.0a1, <= 2.8.10
>= 2.9.0a1, <= 2.9.6
Patched versions
None
Description
Published by the National Vulnerability Database
Mar 16, 2020
Reviewed
Apr 5, 2021
Published to the GitHub Advisory Database
Feb 9, 2022
Last updated
Sep 6, 2024
A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
References