Upstream information

CVE-2014-4967 at MITRE

Description

Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansible managed host and providing a crafted fact, as demonstrated by a fact with (1) a trailing " src=" clause, (2) a trailing " temp=" clause, or (3) a trailing " validate=" clause accompanied by a shell command.

SUSE information

Overall state of this security issue: Does not affect SUSE products

No SUSE Bugzilla entries cross referenced.

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
openSUSE Tumbleweed
  • ansible >= 2.2.0.0-1.1
  • ansible-9 >= 9.8.0-1.1
Patchnames:
openSUSE-Tumbleweed-2024-10326
openSUSE-Tumbleweed-2024-14244


SUSE Timeline for this CVE

CVE page created: Tue Jul 22 16:34:23 2014
CVE page last modified: Tue Sep 3 18:25:55 2024