Severity
5.6MEDIUM
EPSS
0.1%
top 84.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31
Latest updateApr 20

Description

A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:LExploitability: 0.8 | Impact: 4.7

Affected Packages10 packages

NVDredhat/ansible_engine2.7.02.7.16+2
PyPIansible2.7.0a12.7.16+2
Debianansible< 2.9.4+dfsg-1+3
CVEListV5red_hat/ansible4 versions+3

Also affects: Fedora 30

Patches

🔴Vulnerability Details

4
GHSA
Externally Controlled Reference to a Resource in Another Sphere, Improper Input Validation, and External Control of File Name or Path in Ansible2021-04-20
OSV
Externally Controlled Reference to a Resource in Another Sphere, Improper Input Validation, and External Control of File Name or Path in Ansible2021-04-20
CVEList
CVE-2019-14905: A vulnerability was found in Ansible Engine versions 22020-03-31
OSV
CVE-2019-14905: A vulnerability was found in Ansible Engine versions 22020-03-31

📋Vendor Advisories

2
Red Hat
Ansible: malicious code could craft filename in nxos_file_copy module2019-11-27
Debian
CVE-2019-14905: ansible - A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x b...2019

💬Community

4
Bugzilla
CVE-2019-14905 ansible: malicious code could craft filename in nxos_file_copy module [epel-all]2019-11-28
Bugzilla
CVE-2019-14905 ansible: malicious code could craft filename in nxos_file_copy module [openstack-rdo]2019-11-28
Bugzilla
CVE-2019-14905 ansible: malicious code could craft filename in nxos_file_copy module [fedora-all]2019-11-28
Bugzilla
CVE-2019-14905 Ansible: malicious code could craft filename in nxos_file_copy module2019-11-26