发布时间: 2021年9月24日
修改时间: 2021年9月24日
A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
NVD | openEuler | |
---|---|---|
Confidentiality | None | None |
Attack Vector | Local | Local |
CVSS评分 | 3.9 | 3.9 |
Attack Complexity | High | High |
Privileges Required | Low | Low |
Scope | Changed | Changed |
Integrity | Low | Low |
User Interaction | Required | Required |
Availability | Low | Low |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2021-2003 | ansible security update | 2021年9月24日 |
产品 | 包 | 状态 |
---|