CVE-2021-4041
published 2022-08-24CVE-2021-4041: A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters…
PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.31%
22.9th percentile
A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters getting executed as host's shell command. A developer could unintentionally write code that gets executed in the host rather than the virtual environment.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible-runner | < ansible-runner 2.1.1-1 (bookworm) | ansible-runner 2.1.1-1 (bookworm) |
| redhat | ansible_runner | < 2.1.0 | 2.1.0 |
| redhat | ansible_runner | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Ansible: Improper shell escaping in ansible-runner
vendor_redhat·2021-12-01·CVSS 7.8
CVE-2021-4041 [HIGH] CWE-20 Ansible: Improper shell escaping in ansible-runner
Ansible: Improper shell escaping in ansible-runner
A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters getting executed as host's shell command. A developer could unintentionally write code that gets executed in the host rather than the virtual environment.
A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters getting executed as host's shell command. A developer could unintentionally write code that gets executed in the host rather than the virtual environment.
Statement: Satellite 6.12 and later versions are not affected by this flaw.
Package: ansible-runner (CloudForms Managem
Debian
CVE-2021-4041: ansible-runner - A flaw was found in ansible-runner. An improper escaping of the shell command, w...
vendor_debian·2021·CVSS 7.8
CVE-2021-4041 [HIGH] CVE-2021-4041: ansible-runner - A flaw was found in ansible-runner. An improper escaping of the shell command, w...
A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters getting executed as host's shell command. A developer could unintentionally write code that gets executed in the host rather than the virtual environment.
Scope: local
bookworm: resolved (fixed in 2.1.1-1)
forky: resolved (fixed in 2.1.1-1)
sid: resolved (fixed in 2.1.1-1)
trixie: resolved (fixed in 2.1.1-1)
OSV
ansible-runner vulnerable to shell command injection
osv·2022-08-25
CVE-2021-4041 [HIGH] ansible-runner vulnerable to shell command injection
ansible-runner vulnerable to shell command injection
A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the `ansible_runner.interface.run_command`, can lead to parameters getting executed as host's shell command. A developer could unintentionally write code that gets executed in the host rather than the virtual environment.
GHSA
ansible-runner vulnerable to shell command injection
ghsa·2022-08-25
CVE-2021-4041 [HIGH] CWE-116 ansible-runner vulnerable to shell command injection
ansible-runner vulnerable to shell command injection
A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the `ansible_runner.interface.run_command`, can lead to parameters getting executed as host's shell command. A developer could unintentionally write code that gets executed in the host rather than the virtual environment.
OSV
CVE-2021-4041: A flaw was found in ansible-runner
osv·2022-08-24·CVSS 7.8
CVE-2021-4041 [HIGH] CVE-2021-4041: A flaw was found in ansible-runner
A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters getting executed as host's shell command. A developer could unintentionally write code that gets executed in the host rather than the virtual environment.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2021-4041https://bugzilla.redhat.com/show_bug.cgi?id=2028074https://github.com/ansible/ansible-runner/commit/3533f265f4349a3f2a0283158cd01b59a6bbc7bdhttps://access.redhat.com/security/cve/CVE-2021-4041https://bugzilla.redhat.com/show_bug.cgi?id=2028074https://github.com/ansible/ansible-runner/commit/3533f265f4349a3f2a0283158cd01b59a6bbc7bd
2022-08-24
Published