Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ansible 注入漏洞
Vulnerability Description
Ansible是美国Ansible公司的一款计算机系统配置管理器。该产品可用于发布、管理和编排计算机系统。 Ansible 1.6.4之前版本中的‘safe_eval’函数存在注入漏洞,该漏洞源于程序没有正确限制代码子集。远程攻击者可借助特制的指令利用该漏洞执行任意代码。(注意:该漏洞由于CNNVD-201411-451(CVE-2014-4657)的不完整修复所导致。)
CVSS Information
N/A
Vulnerability Type
N/A