CVE-2018-10875 PUBLISHED

A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.

EPSS 0.04% · 13.2th percentile

Risk Scores

EPSS Score
0.04%
13.2th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSansible0, 2.3.1.0+dfsg-2, 2.5.0+dfsg-1
Ubuntu:16.04:LTSansible2.0.0.2-2ubuntu1, 0, 2.0.0.2-2ubuntu1.2

Timeline

References

Open in Interactive Console →