VDB
PYSEC-2018-37
PYSEC-2018-37
PUBLISHED
A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PyPI | ansible | 0, 1.1, 1.2 |
Timeline
- Jul 31, 2018 CVE Published
- Nov 8, 2023 CVE Updated
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8614 report
- http://www.securityfocus.com/bid/94108 url
- https://github.com/advisories/GHSA-cmwx-9m2h-x7v4 advisory
- https://github.com/ansible/ansible-modules-core/pull/5357 fix
- https://github.com/ansible/ansible-modules-core/pull/5353 fix
- https://github.com/ansible/ansible-modules-core/issues/5237 discussion