VDB
KO

PYSEC-2018-38

Details

Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the user Ansible runs as.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / ansible
Introduced in: 0 Fixed in: 2.2.0.0
Fix pip install --upgrade 'ansible>=2.2.0.0'

References