CVE-2014-4967

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in pypi/ansible

Identifiers

GHSA-64cw-m57j-65xj, CVE-2014-4967

Package Slug

pypi/ansible

Vulnerability

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Description

Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansible managed host and providing a crafted fact, as demonstrated by a fact with (1) a trailing " src=" clause, (2) a trailing " temp=" clause, or (3) a trailing " validate=" clause accompanied by a shell command.

Affected Versions

All versions before 1.6.7

Solution

Upgrade to version 1.6.7 or above.

Last Modified

2024-01-31

source