cbcvebase.
CVE-2017-7466
published 2018-06-22

CVE-2017-7466: Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a client…

PriorityP348high8CVSS 3.0
AVNACLPRLUIRSUCHIHAH
EPSS
3.16%
86.5th percentile
Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a client system being managed by Ansible, and the ability to send facts back to the Ansible server, could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianansible< ansible 2.2.1.0-2 (bookworm)ansible 2.2.1.0-2 (bookworm)
redhatansible< 2.32.3
redhatansible>= 0 < 2.2.1.0-22.2.1.0-2
redhatansible>= 0 < 2.2.1.0-22.2.1.0-2
redhatansible>= 0 < 2.2.1.0-22.2.1.0-2
redhatansible>= 0 < 2.2.1.0-22.2.1.0-2
redhatansible>= 0 < 2.2.3.02.2.3.0
redhatopenstack
redhatopenstack

CVSS provenance

nvdv3.08.0HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
osv8.0HIGH
vendor_redhat8.1HIGH
vendor_debian8.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.