CVE-2019-14904

Published Aug 26, 2020

Last updated a year ago

Overview

Description
A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the remote machine. An attacker could take advantage of this flaw by crafting the name of the zone and executing arbitrary commands in the remote host. Ansible Engine 2.7.15, 2.8.7, and 2.9.2 as well as previous versions are affected.
Source
secalert@redhat.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
7.3
Impact score
5.3
Exploitability score
1.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L
Severity
HIGH

CVSS 2.0

Type
Primary
Base score
6.1
Impact score
8.5
Exploitability score
3.9
Vector string
AV:L/AC:L/Au:N/C:C/I:P/A:P

Weaknesses

secalert@redhat.com
CWE-20
nvd@nist.gov
CWE-78

Social media

Hype score
Not currently trending

Configurations