发布时间: 2022年9月23日
修改时间: 2022年9月23日
A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the ps bare command on the remote machine. An attacker could take advantage of this flaw by crafting the name of the zone and executing arbitrary commands in the remote host. Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected.
NVD | openEuler | |
---|---|---|
Confidentiality | High | High |
Attack Vector | Local | Local |
CVSS评分 | 7.3 | 7.3 |
Attack Complexity | Low | Low |
Privileges Required | High | High |
Scope | Changed | Changed |
Integrity | Low | Low |
User Interaction | None | None |
Availability | Low | Low |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2021-2003 | ansible security update | 2021年9月24日 |
KylinSec-SA-2022-2100 | ansible security update | 2022年9月23日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | ansible | Fixed |