CVE-2015-3908: High severity red hat ansible vulnerability
Ansible before 1.9.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Other sources
Ansible versions before 1.9.2 are vulnerable to a symlink attack that enables a malicious zone/chroot/jail managed by ansible to escape into the managing host.
Upstream commits that fix this issue:
https://github.com/ansible/ansible/commit/548a7288a90c49e9b50ccf197da307eae525b899 https://github.com/ansible/ansible/commit/270be6a6f5852c5563976f060c80eff64decc89c https://github.com/ansible/ansible/commit/952166f48eb0f5797b75b160fd156bbe1e8fc647 https://github.com/ansible/ansible/commit/0777d025051bf5cf3092aa79a9e6b67cec7064dd https://github.com/ansible/ansible/commit/ca2f2c4ebd7b5e097eab0a710f79c1f63badf95b
CVE request: http://seclists.org/oss-sec/2015/q3/105
External References:
http://www.ansible.com/security
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3908?
CVE-2015-3908 has a medium severity rating due to its potential to allow man-in-the-middle attacks.
How do I fix CVE-2015-3908?
To fix CVE-2015-3908, upgrade Ansible to version 1.9.2 or later.
Which versions of Ansible are affected by CVE-2015-3908?
Ansible versions prior to 1.9.2, including all versions up to and including 1.9.1, are affected by CVE-2015-3908.
What types of attacks does CVE-2015-3908 allow?
CVE-2015-3908 allows man-in-the-middle attackers to spoof SSL servers using arbitrary valid certificates.
Is my Ansible installation vulnerable if I am using a version below 1.9.2?
Yes, if you are using any version of Ansible below 1.9.2, your installation is vulnerable to CVE-2015-3908.