CVE-2018-10875 HIGH

CVE-2018-10875

Vendor [Unknown]
Product ansible
Weakness CWE-426
Published July 13, 2018
Last update August 5, 2024

CVSS base score

7.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.

Key dates

02Disclosure timeline

July 13, 2018 CVE published
August 5, 2024 Record updated

Related vulnerabilities

04Related CVE