CVE-2017-7466Improper Input Validation in Redhat Ansible

Severity
8.0HIGHNVD
EPSS
2.7%
top 14.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 22
Latest updateMay 13

Description

Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a client system being managed by Ansible, and the ability to send facts back to the Ansible server, could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 2.1 | Impact: 5.9

Affected Packages4 packages

NVDredhat/ansible< 2.3
PyPIredhat/ansible< 2.2.3.0
Debianredhat/ansible< 2.2.1.0-2+3
NVDredhat/openstack10, 11+1

🔴Vulnerability Details

4
OSV
Ansible Arbitrary Code Execution2022-05-13
GHSA
Ansible Arbitrary Code Execution2022-05-13
CVEList
CVE-2017-7466: Ansible before version 22018-06-22
OSV
CVE-2017-7466: Ansible before version 22018-06-22

📋Vendor Advisories

2
Red Hat
ansible: Arbitrary code execution on control node (incomplete fix for CVE-2016-9587)2017-04-11
Debian
CVE-2017-7466: ansible - Ansible before version 2.3 has an input validation vulnerability in the handling...2017

💬Community

5
Bugzilla
CVE-2017-7466 ansible: Arbitrary code execution on control node (incomplete fix for CVE-2016-9587) [epel-all]2017-04-11
Bugzilla
CVE-2017-7466 ansible: Arbitrary code execution on control node (incomplete fix for CVE-2016-9587) [fedora-all]2017-04-11
Bugzilla
CVE-2017-7466 ansible1.9: ansible: Arbitrary code execution on control node (incomplete fix for CVE-2016-9587) [epel-all]2017-04-11
Bugzilla
CVE-2017-7466 ansible1.9: ansible: Arbitrary code execution on control node (incomplete fix for CVE-2016-9587) [fedora-all]2017-04-11
Bugzilla
CVE-2017-7466 ansible: Arbitrary code execution on control node (incomplete fix for CVE-2016-9587)2017-04-05
CVE-2017-7466 — Improper Input Validation in Redhat | cvebase