CVE-2018-10875

A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.

Published : 2018-07-13 22:29 Updated : 2019-07-25 02:15

7.5
CVSS Score More info
Score 7.5 / 10
7.5
Vendor Product Version URI
Redhat Ansible Engine 2.0 cpe:/a:redhat:ansible_engine:2.0
Redhat Ansible Engine 2.4 cpe:/a:redhat:ansible_engine:2.4
Redhat Ansible Engine 2.5 cpe:/a:redhat:ansible_engine:2.5
Redhat Ansible Engine 2.6 cpe:/a:redhat:ansible_engine:2.6
Redhat Openstack 13.0 cpe:/a:redhat:openstack:13.0
Redhat Virtualization 4.0 cpe:/a:redhat:virtualization:4.0
Redhat Openstack 10 cpe:/a:redhat:openstack:10
Redhat Openstack 12 cpe:/a:redhat:openstack:12
Debian Debian Linux 9.0 cpe:/o:debian:debian_linux:9.0
Redhat Ceph Storage 2.0 cpe:/a:redhat:ceph_storage:2.0
Redhat Ceph Storage 3.0 cpe:/a:redhat:ceph_storage:3.0
Redhat Gluster Storage 3.0.0 cpe:/a:redhat:gluster_storage:3.0.0
Redhat Openshift 3.0 cpe:/a:redhat:openshift:3.0::~~enterprise~~~
Redhat Virtualization Host 4.0 cpe:/a:redhat:virtualization_host:4.0
Suse Package Hub - cpe:/a:suse:package_hub:-
  1. Debian (1) Search CVE
    1. Debian Linux (1) Search CVE
      1. 9.0
  2. Redhat (7) Search CVE
    1. Ansible Engine (4) Search CVE
      1. 2.0
      2. 2.4
      3. 2.5
      4. 2.6
    2. Openshift (1) Search CVE
      1. 3.0
    3. Virtualization (1) Search CVE
      1. 4.0
    4. Gluster Storage (1) Search CVE
      1. 3.0.0
    5. Openstack (3) Search CVE
      1. 13.0
      2. 10
      3. 12
    6. Ceph Storage (2) Search CVE
      1. 2.0
      2. 3.0
    7. Virtualization Host (1) Search CVE
      1. 4.0
  3. Suse (1) Search CVE
    1. Package Hub (1) Search CVE
      1. -

CWE

ID Name Description Links
CWE-426 Untrusted Search Path The application searches for critical resources using an externally-supplied search path that can point to resources that are not under the application's direct control. CVE

History of changes

Date Event
2019-07-25 02:15
2019-05-10 19:21
2019-03-02 00:12
2019-02-20 11:29
2019-01-17 11:29
2018-12-06 11:29
2018-09-10 13:58
2018-08-30 10:29
2018-08-02 01:29
2018-07-15 01:29
2018-07-13 22:29

New CVE