CVE-2014-4657
published 2020-02-20CVE-2014-4657: The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted…
PriorityP357critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.39%
90.2th percentile
The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 1.5.5+dfsg-1 (bookworm) | ansible 1.5.5+dfsg-1 (bookworm) |
| debian | ansible | < ansible 1.6.6+dfsg-1 (bookworm) | ansible 1.6.6+dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| redhat | ansible | < 1.5.4 | 1.5.4 |
| redhat | ansible | < 1.6.4 | 1.6.4 |
| redhat | ansible | — | — |
| redhat | ansible | >= 0 < 1.6.6+dfsg-1 | 1.6.6+dfsg-1 |
| redhat | ansible | >= 0 < 1.5.5+dfsg-1 | 1.5.5+dfsg-1 |
| redhat | ansible | >= 0 < 1.6.6+dfsg-1 | 1.6.6+dfsg-1 |
| redhat | ansible | >= 0 < 1.5.5+dfsg-1 | 1.5.5+dfsg-1 |
| redhat | ansible | >= 0 < 1.6.6+dfsg-1 | 1.6.6+dfsg-1 |
| redhat | ansible | >= 0 < 1.5.5+dfsg-1 | 1.5.5+dfsg-1 |
| redhat | ansible | >= 0 < 1.6.6+dfsg-1 | 1.6.6+dfsg-1 |
| redhat | ansible | >= 0 < 1.5.5+dfsg-1 | 1.5.5+dfsg-1 |
| redhat | ansible | >= 0 < 1.5.4 | 1.5.4 |
| redhat | ansible | >= 0 < 1.6.4 | 1.6.4 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ansible: safe_eval function does not properly restrict the code subset leads to arbitrary code execution via crafted instructions
vendor_redhat·2020-02-19·CVSS 9.8
CVE-2014-4678 [CRITICAL] CWE-94 ansible: safe_eval function does not properly restrict the code subset leads to arbitrary code execution via crafted instructions
ansible: safe_eval function does not properly restrict the code subset leads to arbitrary code execution via crafted instructions
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.
A flaw was found in ansible. The safe_eval function does not properly restrict the code subset which allows remote attackers to execute arbitrary code via crafted instructions. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: Red Hat Ceph Storage and Red Hat Gluster Storage shipped ansible versions 2.4.1 and 2.3.2 respectively, which
Red Hat
ansible: improper restriction of code subset allows remote arbitrary code execution via crafted instructions
vendor_redhat·2014-04-01·CVSS 9.8
CVE-2014-4657 [CRITICAL] CWE-20 ansible: improper restriction of code subset allows remote arbitrary code execution via crafted instructions
ansible: improper restriction of code subset allows remote arbitrary code execution via crafted instructions
The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.
A flaw was found in the safe_eval function in Ansible before 1.5.4, where it does not properly restrict the code subset. This flaw allows remote attackers to execute arbitrary code via crafted instructions.
Package: ansible (CloudForms Management Engine 5) - Not affected
Package: ansible (Red Hat Ansible Engine 2) - Not affected
Package: ansible (Red Hat Ansible Tower 3) - Not affected
Package: ansible (Red Hat Ceph Storage 2) - Not affected
Package: ansible (Red Hat Ceph Storage 3) - Not affected
Package
Debian
CVE-2014-4657: ansible - The safe_eval function in Ansible before 1.5.4 does not properly restrict the co...
vendor_debian·2014·CVSS 9.8
CVE-2014-4657 [CRITICAL] CVE-2014-4657: ansible - The safe_eval function in Ansible before 1.5.4 does not properly restrict the co...
The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.
Scope: local
bookworm: resolved (fixed in 1.5.5+dfsg-1)
bullseye: resolved (fixed in 1.5.5+dfsg-1)
forky: resolved (fixed in 1.5.5+dfsg-1)
sid: resolved (fixed in 1.5.5+dfsg-1)
trixie: resolved (fixed in 1.5.5+dfsg-1)
Debian
CVE-2014-4678: ansible - The safe_eval function in Ansible before 1.6.4 does not properly restrict the co...
vendor_debian·2014·CVSS 9.8
CVE-2014-4678 [CRITICAL] CVE-2014-4678: ansible - The safe_eval function in Ansible before 1.6.4 does not properly restrict the co...
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.
Scope: local
bookworm: resolved (fixed in 1.6.6+dfsg-1)
bullseye: resolved (fixed in 1.6.6+dfsg-1)
forky: resolved (fixed in 1.6.6+dfsg-1)
sid: resolved (fixed in 1.6.6+dfsg-1)
trixie: resolved (fixed in 1.6.6+dfsg-1)
GHSA
Ansible Code Injection Vulnerability
ghsa·2022-05-24·CVSS 9.8
CVE-2014-4678 [CRITICAL] CWE-74 Ansible Code Injection Vulnerability
Ansible Code Injection Vulnerability
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.
OSV
Ansible Code Injection Vulnerability
osv·2022-05-24·CVSS 9.8
CVE-2014-4678 [CRITICAL] Ansible Code Injection Vulnerability
Ansible Code Injection Vulnerability
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.
GHSA
Ansible Remote Code Execution
ghsa·2022-05-17
CVE-2014-4657 [CRITICAL] CWE-20 Ansible Remote Code Execution
Ansible Remote Code Execution
The `safe_eval` function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.
OSV
Ansible Remote Code Execution
osv·2022-05-17
CVE-2014-4657 [CRITICAL] Ansible Remote Code Execution
Ansible Remote Code Execution
The `safe_eval` function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.
OSV
CVE-2014-4678: The safe_eval function in Ansible before 1
osv·2020-02-20·CVSS 9.8
CVE-2014-4678 [CRITICAL] CVE-2014-4678: The safe_eval function in Ansible before 1
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.
OSV
CVE-2014-4657: The safe_eval function in Ansible before 1
osv·2020-02-20·CVSS 9.8
CVE-2014-4657 [CRITICAL] CVE-2014-4657: The safe_eval function in Ansible before 1
The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-4657 ansible: improper restriction of code subset allows remote arbitrary code execution via crafted instructions [fedora-all]
bugzilla·2020-05-04·CVSS 9.8
CVE-2014-4657 [CRITICAL] CVE-2014-4657 ansible: improper restriction of code subset allows remote arbitrary code execution via crafted instructions [fedora-all]
CVE-2014-4657 ansible: improper restriction of code subset allows remote arbitrary code execution via crafted instructions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit mess
Bugzilla
CVE-2014-4657 ansible: improper restriction of code subset allows remote arbitrary code execution via crafted instructions [epel-all]
bugzilla·2020-05-04·CVSS 9.8
CVE-2014-4657 [CRITICAL] CVE-2014-4657 ansible: improper restriction of code subset allows remote arbitrary code execution via crafted instructions [epel-all]
CVE-2014-4657 ansible: improper restriction of code subset allows remote arbitrary code execution via crafted instructions [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2014-4657 ansible: improper restriction of code subset allows remote arbitrary code execution via crafted instructions
bugzilla·2020-05-04·CVSS 9.8
CVE-2014-4657 [CRITICAL] CVE-2014-4657 ansible: improper restriction of code subset allows remote arbitrary code execution via crafted instructions
CVE-2014-4657 ansible: improper restriction of code subset allows remote arbitrary code execution via crafted instructions
The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.
References:
https://github.com/ansible/ansible/blob/release1.5.5/CHANGELOG.md
https://www.securityfocus.com/bid/68232
Discussion:
Created ansible tracking bugs for this issue:
Affects: epel-all [bug 1831265]
Affects: fedora-all [bug 1831264]
---
Red Hat CloudForms 5.10 (4.7) and 5.11 (5.0) do not ship `ansible` package, it is provided by the official Ansible repository.
---
This is a bug for Ansible 1.5.4 and previous versions, really old, and fixed on 1.5.5 and after long time ago, when i
Bugzilla
CVE-2014-4678 ansible: safe_eval function does not properly restrict the code subset leads to arbitrary code execution via crafted instructions
bugzilla·2020-04-28·CVSS 9.8
CVE-2014-4678 [CRITICAL] CVE-2014-4678 ansible: safe_eval function does not properly restrict the code subset leads to arbitrary code execution via crafted instructions
CVE-2014-4678 ansible: safe_eval function does not properly restrict the code subset leads to arbitrary code execution via crafted instructions
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.
Reference:
https://github.com/ansible/ansible/commit/5429b85b9f6c2e640074176f36ff05fd5e4d1916
https://groups.google.com/forum/message/raw?msg=ansible-announce/ieV1vZvcTXU/5Q93ThkY9rIJ
https://www.openwall.com/lists/oss-security/2014/06/26/30
https://www.openwall.com/lists/oss-security/2014/07/02/2
Discussion:
This bug is now closed. Further updates for individual products will be reflected on the
2020-02-20
Published