GHSA-64cw-m57j-65xj, CVE-2014-4967
pypi/ansible
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansible managed host and providing a crafted fact, as demonstrated by a fact with (1) a trailing " src=" clause, (2) a trailing " temp=" clause, or (3) a trailing " validate=" clause accompanied by a shell command.
All versions before 1.6.7
Upgrade to version 1.6.7 or above.
2024-01-31
source |