CVE-2015-6240: High severity red hat ansible vulnerability
Published Jun 7, 2017
·Updated
Last updated 10 March 2025
Other sources
The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environment via a symlink attack.
— MITRE
Affected Software
3 affected componentsFixes available
pip/ansible<1.9.2
1.9.2
redhat ansible<=1.9.1
debian/ansible
2.10.7+merged+base+2.10.17+dfsg-0+deb11u12.10.7+merged+base+2.10.17+dfsg-0+deb11u27.7.0+dfsg-3+deb12u111.2.0+dfsg-1
Remediation
Event History
Jun 7, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
May 13, 2022
Advisory Published
via GitHub·01:54 AM
Mar 6, 2025
Data Sourced
via Launchpad·08:53 PM
Description
Mar 10, 2025
Data Sourced
via Ubuntu·08:54 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2015-6240?
CVE-2015-6240 is classified as a medium severity vulnerability, allowing local users to escape restricted environments.
2
How do I fix CVE-2015-6240?
To fix CVE-2015-6240, upgrade to Ansible version 1.9.2 or later.
3
Who is affected by CVE-2015-6240?
Local users operating on Ansible versions prior to 1.9.2 and Red Hat Ansible versions up to 1.9.1 are affected by CVE-2015-6240.
4
What types of attacks does CVE-2015-6240 allow?
CVE-2015-6240 allows attackers to perform symlink attacks leading to unauthorized access outside the restricted environment.
5
Is CVE-2015-6240 related to specific Ansible plugins?
Yes, CVE-2015-6240 affects the chroot, jail, and zone connection plugins in Ansible.