—
PYSEC-2020-6
상세
A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could take advantage and run arbitrary commands by overwriting the ansible facts.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.