CVE-2018-10874 PUBLISHED

In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.

EPSS 0.05% · 14.3th percentile

Risk Scores

EPSS Score
0.05%
14.3th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSansible0, 2.3.1.0+dfsg-2, 2.5.0+dfsg-1

Timeline

References

Open in Interactive Console →