CVE-2014-2686: High severity red hat ansible vulnerability
Published Jan 9, 2020
·Updated
Ansible prior to 1.5.4 mishandles the evaluation of some strings.
Affected Software
2 affected componentsFixes available
pip/ansible<1.5.4
1.5.4
redhat ansible<1.5.4
Event History
Jan 9, 2020
CVE Published
via MITRE·12:25 PM
Data Sourced
via MITRE·12:25 PM
Description
May 17, 2022
Advisory Published
07:57 PM
Frequently Asked Questions
1
What is CVE-2014-2686?
CVE-2014-2686 is a vulnerability in Ansible prior to version 1.5.4 that mishandles the evaluation of some strings.
2
What is the severity of CVE-2014-2686?
The severity of CVE-2014-2686 is high with a CVSS score of 7.5.
3
How does CVE-2014-2686 affect Ansible?
CVE-2014-2686 affects Ansible versions prior to 1.5.4.
4
How can I fix CVE-2014-2686?
To fix CVE-2014-2686, update Ansible to version 1.5.4 or later.
5
Where can I find more information about CVE-2014-2686?
You can find more information about CVE-2014-2686 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2014-2686), [Ansible Google Group](https://groups.google.com/forum/#!searchin/ansible-project/1.5.4/ansible-project/MUQxiKwSQDc/id6aVaawVboJ), [Ansible GitHub Commit](https://github.com/ansible/ansible/commit/998793fd0ab55705d57527a38cee5e83f535974c).