CVE-2014-4678
published 2020-02-20CVE-2014-4678: The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
5.20%
91.5th percentile
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 1.6.6+dfsg-1 (bookworm) | ansible 1.6.6+dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| redhat | ansible | < 1.6.4 | 1.6.4 |
| redhat | ansible | >= 0 < 1.6.6+dfsg-1 | 1.6.6+dfsg-1 |
| redhat | ansible | >= 0 < 1.6.6+dfsg-1 | 1.6.6+dfsg-1 |
| redhat | ansible | >= 0 < 1.6.6+dfsg-1 | 1.6.6+dfsg-1 |
| redhat | ansible | >= 0 < 1.6.6+dfsg-1 | 1.6.6+dfsg-1 |
| redhat | ansible | >= 0 < 1.6.4 | 1.6.4 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Ansible Code Injection Vulnerability
ghsa·2022-05-24·CVSS 9.8
CVE-2014-4678 [CRITICAL] CWE-74 Ansible Code Injection Vulnerability
Ansible Code Injection Vulnerability
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.
OSV
Ansible Code Injection Vulnerability
osv·2022-05-24·CVSS 9.8
CVE-2014-4678 [CRITICAL] Ansible Code Injection Vulnerability
Ansible Code Injection Vulnerability
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.
OSV
CVE-2014-4678: The safe_eval function in Ansible before 1
osv·2020-02-20·CVSS 9.8
CVE-2014-4678 [CRITICAL] CVE-2014-4678: The safe_eval function in Ansible before 1
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.
Red Hat
ansible: safe_eval function does not properly restrict the code subset leads to arbitrary code execution via crafted instructions
vendor_redhat·2020-02-19·CVSS 9.8
CVE-2014-4678 [CRITICAL] CWE-94 ansible: safe_eval function does not properly restrict the code subset leads to arbitrary code execution via crafted instructions
ansible: safe_eval function does not properly restrict the code subset leads to arbitrary code execution via crafted instructions
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.
A flaw was found in ansible. The safe_eval function does not properly restrict the code subset which allows remote attackers to execute arbitrary code via crafted instructions. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: Red Hat Ceph Storage and Red Hat Gluster Storage shipped ansible versions 2.4.1 and 2.3.2 respectively, which
Debian
CVE-2014-4678: ansible - The safe_eval function in Ansible before 1.6.4 does not properly restrict the co...
vendor_debian·2014·CVSS 9.8
CVE-2014-4678 [CRITICAL] CVE-2014-4678: ansible - The safe_eval function in Ansible before 1.6.4 does not properly restrict the co...
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.
Scope: local
bookworm: resolved (fixed in 1.6.6+dfsg-1)
bullseye: resolved (fixed in 1.6.6+dfsg-1)
forky: resolved (fixed in 1.6.6+dfsg-1)
sid: resolved (fixed in 1.6.6+dfsg-1)
trixie: resolved (fixed in 1.6.6+dfsg-1)
No detection rules found.
No public exploits indexed.
https://github.com/ansible/ansible/commit/5429b85b9f6c2e640074176f36ff05fd5e4d1916https://groups.google.com/forum/message/raw?msg=ansible-announce/ieV1vZvcTXU/5Q93ThkY9rIJhttps://security-tracker.debian.org/tracker/CVE-2014-4678https://www.openwall.com/lists/oss-security/2014/06/26/30https://www.openwall.com/lists/oss-security/2014/07/02/2https://www.rapid7.com/db/vulnerabilities/freebsd-vid-2c493ac8-205e-11e5-a4a5-002590263bf5https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2014-4678https://github.com/ansible/ansible/commit/5429b85b9f6c2e640074176f36ff05fd5e4d1916https://groups.google.com/forum/message/raw?msg=ansible-announce/ieV1vZvcTXU/5Q93ThkY9rIJhttps://security-tracker.debian.org/tracker/CVE-2014-4678https://www.openwall.com/lists/oss-security/2014/06/26/30https://www.openwall.com/lists/oss-security/2014/07/02/2https://www.rapid7.com/db/vulnerabilities/freebsd-vid-2c493ac8-205e-11e5-a4a5-002590263bf5https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2014-4678
2020-02-20
Published