CyberSec.Space Logo
CVEブラウザに戻る

CVE-2014-4678

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0850%
EPSS Percentile10.87th
Published2020年2月20日
Last Modified2024年11月21日

Vulnerability Description

The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.

Affected Platforms (CPE)

📦
Redhat

Ansible

< 1.6.4
💻
Debian

Debian Linux

= 8.0
💻
Debian

Debian Linux

= 9.0
💻
Debian

Debian Linux

= 10.0

References & Advisories

関連する脆弱性情報