CVE-2019-14905
published 2020-03-31CVE-2019-14905: A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy…
PriorityP427medium5.6CVSS 3.1
AVLACLPRHUINSUCHILAL
EPSS
0.74%
50.3th percentile
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 2.9.4+dfsg-1 (bookworm) | ansible 2.9.4+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| redhat | ansible | >= 0 < 2.9.4+dfsg-1 | 2.9.4+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.4+dfsg-1 | 2.9.4+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.4+dfsg-1 | 2.9.4+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.4+dfsg-1 | 2.9.4+dfsg-1 |
| redhat | ansible | >= 2.7.0a1 < 2.7.16 | 2.7.16 |
| redhat | ansible | >= 2.8.0a1 < 2.8.8 | 2.8.8 |
| redhat | ansible | >= 2.9.0a1 < 2.9.3 | 2.9.3 |
| redhat | ansible_engine | >= 2.7.0 < 2.7.16 | 2.7.16 |
| redhat | ansible_engine | >= 2.8.0 < 2.8.8 | 2.8.8 |
| redhat | ansible_engine | >= 2.9.0 < 2.9.3 | 2.9.3 |
| redhat | ansible_tower | — | — |
| redhat | ceph_storage | — | — |
| redhat | cloudforms_management_engine | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
nvdv3.07.3HIGHCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv5.6MEDIUM
vendor_debian5.6LOW
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Externally Controlled Reference to a Resource in Another Sphere, Improper Input Validation, and External Control of File Name or Path in Ansible
ghsa·2021-04-20
CVE-2019-14905 [HIGH] CWE-20 Externally Controlled Reference to a Resource in Another Sphere, Improper Input Validation, and External Control of File Name or Path in Ansible
Externally Controlled Reference to a Resource in Another Sphere, Improper Input Validation, and External Control of File Name or Path in Ansible
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.
OSV
Externally Controlled Reference to a Resource in Another Sphere, Improper Input Validation, and External Control of File Name or Path in Ansible
osv·2021-04-20
CVE-2019-14905 [HIGH] Externally Controlled Reference to a Resource in Another Sphere, Improper Input Validation, and External Control of File Name or Path in Ansible
Externally Controlled Reference to a Resource in Another Sphere, Improper Input Validation, and External Control of File Name or Path in Ansible
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.
OSV
CVE-2019-14905: A vulnerability was found in Ansible Engine versions 2
osv·2020-03-31·CVSS 5.6
CVE-2019-14905 [MEDIUM] CVE-2019-14905: A vulnerability was found in Ansible Engine versions 2
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.
Red Hat
Ansible: malicious code could craft filename in nxos_file_copy module
vendor_redhat·2019-11-27·CVSS 5.6
CVE-2019-14905 [MEDIUM] CWE-88 Ansible: malicious code could craft filename in nxos_file_copy module
Ansible: malicious code could craft filename in nxos_file_copy module
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.
A vulnerability in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.
Statement: Ansible Engine 2.7.15, 2.8.7, and
Debian
CVE-2019-14905: ansible - A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x b...
vendor_debian·2019·CVSS 5.6
CVE-2019-14905 [MEDIUM] CVE-2019-14905: ansible - A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x b...
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.
Scope: local
bookworm: resolved (fixed in 2.9.4+dfsg-1)
bullseye: resolved (fixed in 2.9.4+dfsg-1)
forky: resolved (fixed in 2.9.4+dfsg-1)
sid: resolved (fixed in 2.9.4+dfsg-1)
trixie: resolved (fixed in 2.9.4+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14905 ansible: malicious code could craft filename in nxos_file_copy module [epel-all]
bugzilla·2019-11-28·CVSS 5.6
CVE-2019-14905 [MEDIUM] CVE-2019-14905 ansible: malicious code could craft filename in nxos_file_copy module [epel-all]
CVE-2019-14905 ansible: malicious code could craft filename in nxos_file_copy module [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2019-14905 ansible: malicious code could craft filename in nxos_file_copy module [openstack-rdo]
bugzilla·2019-11-28·CVSS 5.6
CVE-2019-14905 [MEDIUM] CVE-2019-14905 ansible: malicious code could craft filename in nxos_file_copy module [openstack-rdo]
CVE-2019-14905 ansible: malicious code could craft filename in nxos_file_copy module [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Fixed by upda
Bugzilla
CVE-2019-14905 ansible: malicious code could craft filename in nxos_file_copy module [fedora-all]
bugzilla·2019-11-28·CVSS 5.6
CVE-2019-14905 [MEDIUM] CVE-2019-14905 ansible: malicious code could craft filename in nxos_file_copy module [fedora-all]
CVE-2019-14905 ansible: malicious code could craft filename in nxos_file_copy module [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2019-14905 Ansible: malicious code could craft filename in nxos_file_copy module
bugzilla·2019-11-26·CVSS 5.6
CVE-2019-14905 [MEDIUM] CVE-2019-14905 Ansible: malicious code could craft filename in nxos_file_copy module
CVE-2019-14905 Ansible: malicious code could craft filename in nxos_file_copy module
A vulnerability has been found in nxos_file_copy from Ansible module. Filenames are used to perform actions to copy files to a flash or bootflash on NXOS devices. However, nxos_file_copy takes remote_file parameter which is used for destination. Malicious code could crafts the filename parameter to take advantage by performing an OS command injection.
Discussion:
Acknowledgments:
Name: Abhijeet Kasurde (Red Hat)
---
Created ansible tracking bugs for this issue:
Affects: epel-all [bug 1777693]
Affects: fedora-all [bug 1777692]
Affects: openstack-rdo [bug 1777691]
---
Adding Ganesh Nalawade who is fixing this issue.
---
PR fixed and merged to devel https://github.com/ansible/ansible/pull/65423
Bac
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.htmlhttps://access.redhat.com/errata/RHSA-2020:0216https://access.redhat.com/errata/RHSA-2020:0218https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14905https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5BNCYPQ4BY5QHBCJOAOPANB5FHATW2BR/http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.htmlhttps://access.redhat.com/errata/RHSA-2020:0216https://access.redhat.com/errata/RHSA-2020:0218https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14905https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5BNCYPQ4BY5QHBCJOAOPANB5FHATW2BR/
2020-03-31
Published