Alerts This Week
Warning Icon 1 758
Alerts This Week
Warning Icon 1 758

Debian 9: DLA-2536-2 Critical: Ansible Command Execution Issue

debian lts
Calendar Grey January 27, 2021
Dist Debian Esm H88
Update Ansible on Debian 9 for critical security flaws to prevent code execution risks. Get secure today!
CVE-2017-7481 Ansible fails to properly mark lookup-plugin results as unsafe

Summary

CVE-2019-10156

A flaw was discovered in the way Ansible templating was implemented,
causing the possibility of information disclosure through unexpected
variable substitution. By taking advantage of unintended variable
substitution the content of any variable may be disclosed.

CVE-2019-14846

Ansible was logging at the DEBUG level which lead to a disclosure of
credentials if a plugin used a library that logged credentials at the DEBUG
level. This flaw does not affect Ansible modules, as those are executed in
a separate process.

CVE-2019-14904

A flaw was found in the solaris_zone module from the Ansible Community
modules. When setting the name for the zone on the Solaris host, the zone
name is checked by listing the process with the 'ps' bare command on the
remote machine. An attacker could take advantage of this flaw by crafting
the name of the zone and executing arbitrary commands in the remote host.

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

-------------------------------------------------------------------------Package: ansible
Version: 2.2.1.0-2+deb9u2
CVE ID: CVE-2017-7481 CVE-2019-10156 CVE-2019-14846
Debian Bug: 862666 930065 942188

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here