CVE-2014-3498
published 2017-06-08CVE-2014-3498: The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands.
PriorityP354high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.50%
82.9th percentile
The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 1.7.0+dfsg-1 (bookworm) | ansible 1.7.0+dfsg-1 (bookworm) |
| redhat | ansible | <= 1.6.5 | — |
| redhat | ansible | >= 0 < 1.7.0+dfsg-1 | 1.7.0+dfsg-1 |
| redhat | ansible | >= 0 < 1.7.0+dfsg-1 | 1.7.0+dfsg-1 |
| redhat | ansible | >= 0 < 1.7.0+dfsg-1 | 1.7.0+dfsg-1 |
| redhat | ansible | >= 0 < 1.7.0+dfsg-1 | 1.7.0+dfsg-1 |
| redhat | ansible | >= 0 < 1.6.6 | 1.6.6 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Ansible Arbitrary Code Execution
osv·2022-05-14
CVE-2014-3498 [HIGH] Ansible Arbitrary Code Execution
Ansible Arbitrary Code Execution
User module in ansible before 1.6.6 is vulnerable to command execution. Ansible can get the result of remote command in variable, which may come from untrusted source of input. If the content of variable isn't properly filtered and when attempting to use the variable, it will trigger a function that passes it through jinja 2 template engine that can result into arbitrary command execution. Under certain circumstances, unprivileged user on system that is being managed via ansible can execute code on the managing host under UID of running ansible process.
GHSA
Ansible Arbitrary Code Execution
ghsa·2022-05-14
CVE-2014-3498 [HIGH] CWE-20 Ansible Arbitrary Code Execution
Ansible Arbitrary Code Execution
User module in ansible before 1.6.6 is vulnerable to command execution. Ansible can get the result of remote command in variable, which may come from untrusted source of input. If the content of variable isn't properly filtered and when attempting to use the variable, it will trigger a function that passes it through jinja 2 template engine that can result into arbitrary command execution. Under certain circumstances, unprivileged user on system that is being managed via ansible can execute code on the managing host under UID of running ansible process.
OSV
CVE-2014-3498: The user module in ansible before 1
osv·2017-06-08·CVSS 8.8
CVE-2014-3498 [HIGH] CVE-2014-3498: The user module in ansible before 1
The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands.
Red Hat
ansible: Potential untrusted template execution
vendor_redhat·2014-06-30·CVSS 8.8
CVE-2014-3498 [HIGH] CWE-20 ansible: Potential untrusted template execution
ansible: Potential untrusted template execution
The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands.
Package: ansible (Red Hat OpenShift Enterprise 3) - Not affected
Debian
CVE-2014-3498: ansible - The user module in ansible before 1.6.6 allows remote authenticated users to exe...
vendor_debian·2014·CVSS 8.8
CVE-2014-3498 [HIGH] CVE-2014-3498: ansible - The user module in ansible before 1.6.6 allows remote authenticated users to exe...
The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands.
Scope: local
bookworm: resolved (fixed in 1.7.0+dfsg-1)
bullseye: resolved (fixed in 1.7.0+dfsg-1)
forky: resolved (fixed in 1.7.0+dfsg-1)
sid: resolved (fixed in 1.7.0+dfsg-1)
trixie: resolved (fixed in 1.7.0+dfsg-1)
No detection rules found.
No public exploits indexed.
2017-06-08
Published