CVE-2015-3908: High severity red hat ansible vulnerability

Published Jul 15, 2015
·
Updated

Ansible before 1.9.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Other sources

Ansible versions before 1.9.2 are vulnerable to a symlink attack that enables a malicious zone/chroot/jail managed by ansible to escape into the managing host.

Upstream commits that fix this issue:

https://github.com/ansible/ansible/commit/548a7288a90c49e9b50ccf197da307eae525b899 https://github.com/ansible/ansible/commit/270be6a6f5852c5563976f060c80eff64decc89c https://github.com/ansible/ansible/commit/952166f48eb0f5797b75b160fd156bbe1e8fc647 https://github.com/ansible/ansible/commit/0777d025051bf5cf3092aa79a9e6b67cec7064dd https://github.com/ansible/ansible/commit/ca2f2c4ebd7b5e097eab0a710f79c1f63badf95b

CVE request: http://seclists.org/oss-sec/2015/q3/105

External References:

http://www.ansible.com/security

Red Hat

Affected Software

4 affected componentsFixes available
redhat/Ansible<1.9.2
1.9.2
pip/ansible<1.9.2
1.9.2
redhat ansible<=1.9.1
debian/ansible
2.10.7+merged+base+2.10.17+dfsg-0+deb11u12.10.7+merged+base+2.10.17+dfsg-0+deb11u27.7.0+dfsg-3+deb12u111.2.0+dfsg-1

Event History

Aug 12, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Oct 10, 2018
Advisory Published
via GitHub·05:23 PM
Mar 6, 2025
Data Sourced
via Launchpad·08:53 PM
Description
Mar 10, 2025
Data Sourced
via Ubuntu·08:54 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2015-3908?

CVE-2015-3908 has a medium severity rating due to its potential to allow man-in-the-middle attacks.

2

How do I fix CVE-2015-3908?

To fix CVE-2015-3908, upgrade Ansible to version 1.9.2 or later.

3

Which versions of Ansible are affected by CVE-2015-3908?

Ansible versions prior to 1.9.2, including all versions up to and including 1.9.1, are affected by CVE-2015-3908.

4

What types of attacks does CVE-2015-3908 allow?

CVE-2015-3908 allows man-in-the-middle attackers to spoof SSL servers using arbitrary valid certificates.

5

Is my Ansible installation vulnerable if I am using a version below 1.9.2?

Yes, if you are using any version of Ansible below 1.9.2, your installation is vulnerable to CVE-2015-3908.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203