peter bassill · operator
$ cve CVE-2016-9587 JSON

CVE-2016-9587 EXPLOIT

8.1
HIGH · CVSS 3.1 · EPSS 17.5% (pctl 97)

Patch early

A public exploit exists.

Description

Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.

Scoring

CVSS8.1 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS17.45% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2018-04-24
Last modified2026-06-17

Affected (3)

VendorProduct
ansibleansible
redhatansible
redhatopenstack

Public exploits

SourceTitleDate
exploit-dbAnsible 2.1.4/2.2.1 - Command Execution2017-01-09

References

→ the Explorer  ·  watch your stack  ·  NVD