[WID-SEC-2023-2482] Ansible: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode CVSS Base Score 8.8 (hoch) CVSS Temporal Score 7.7 (hoch) Remoteangriff ja Datum 08.12.2019 Stand UPDATE 08.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux UNIX Produktbeschreibung Ansible ist eine Software zur Automatisierung von Cloud Provisionierung, zum Konfigurationsmanagement und zur Anwendungsbereitstellung. Produkte UPDATE 06.03.2025 Ubuntu Linux UPDATE 03.12.2024 SUSE openSUSE UPDATE 27.09.2023 Amazon Linux 2 UPDATE 27.01.2021 Debian Linux UPDATE 12.11.2020 SUSE Linux UPDATE 23.01.2020 Red Hat Enterprise Linux 08.12.2019 Open Source Ansible 2.7.x Open Source Ansible 2.8.x Open Source Ansible 2.9.x Angriff Angriff Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Ansible ausnutzen, um beliebigen Programmcode auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple vulnerabilities in Ansible (CVSS Base Score 8.8) allow a remote authenticated attacker to execute arbitrary code. The affected versions include Ansible open source versions 2.7.x, 2.8.x, and 2.9.x. Mitigations are available, and updates have been issued by major Linux distributions including Ubuntu, SUSE, Amazon Linux 2, Debian, and Red Hat Enterprise Linux.