CVE-2014-4678 PUBLISHED

The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.

EPSS 4.73% · 89.3th percentile

Risk Scores

EPSS Score
4.73%
89.3th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSansible0, 1.1+dfsg-1, 1.3.4+dfsg-1

Timeline

References

Open in Interactive Console →