CVE-2014-4966: Critical severity red hat ansible vulnerability
Published Feb 18, 2020
·Updated
Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which allows remote attackers to execute arbitrary code via (1) crafted lookup('pipe') calls or (2) crafted Jinja2 data.
Affected Software
2 affected componentsFixes available
pip/ansible<1.6.7
1.6.7
redhat ansible<1.6.7
Remediation
Event History
Feb 18, 2020
CVE Published
via MITRE·02:46 PM
Data Sourced
via MITRE·02:46 PM
Description
May 17, 2022
Advisory Published
via GitHub·07:57 PM
Frequently Asked Questions
1
What is CVE-2014-4966?
CVE-2014-4966 is a vulnerability in Ansible before version 1.6.7 that allows remote attackers to execute arbitrary code.
2
What is the severity of CVE-2014-4966?
CVE-2014-4966 has a severity rating of 9.8, which is considered critical.
3
How does CVE-2014-4966 allow attackers to execute arbitrary code?
CVE-2014-4966 allows attackers to execute arbitrary code through crafted lookup('pipe') calls or crafted Jinja2 data.
4
What software is affected by CVE-2014-4966?
CVE-2014-4966 affects Ansible versions before 1.6.7.
5
How can I fix CVE-2014-4966?
To fix CVE-2014-4966, update to Ansible version 1.6.7 or later.