Description
The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environment via a symlink attack.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: High
Availability: High
Affected Packages3 packages
🔴Vulnerability Details
5OSVansible vulnerabilities↗2025-03-05 ▶ GHSAAnsible Sandbox Escape via Symlink Attack↗2022-05-13 ▶ OSVAnsible Sandbox Escape via Symlink Attack↗2022-05-13 ▶ CVEListCVE-2015-6240: The chroot, jail, and zone connection plugins in ansible before 1↗2017-06-07 ▶ OSVCVE-2015-6240: The chroot, jail, and zone connection plugins in ansible before 1↗2017-06-07 ▶ 📋Vendor Advisories
3UbuntuAnsible vulnerabilities↗2025-03-05 ▶ Red Hatansible: multiple issues fixed in 1.9.2↗2015-06-19 ▶ DebianCVE-2015-6240: ansible - The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow loca...↗2015 ▶ 💬Community
1BugzillaCVE-2015-6240 CVE-2015-3908 ansible: multiple issues fixed in 1.9.2↗2015-07-15 ▶