CVE-2018-10874: Input Validation
Published Jun 29, 2018
·Updated
In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.
Affected Software
13 affected componentsFixes available
pip/ansible>=2.6<2.6.1
2.6.1
pip/ansible>=2.5<2.5.6
2.5.6
pip/ansible>=0<2.4.6.0
2.4.6.0
redhat Ansible Engine=2.0
redhat Ansible Engine=2.4
redhat Ansible Engine=2.5
redhat Ansible Engine=2.6
redhat Openstack=10
redhat Openstack=12
redhat Openstack=13
redhat Virtualization=4.0
redhat Virtualization Host=4.0
debian/ansible
2.10.7+merged+base+2.10.17+dfsg-0+deb11u12.10.7+merged+base+2.10.17+dfsg-0+deb11u47.7.0+dfsg-3+deb12u112.0.0+dfsg-0+deb13u113.4.0+dfsg-1
Event History
Jun 29, 2018
Data Sourced
via Red Hat·07:56 AM
DescriptionSeverityAffected Software
Jul 2, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness
May 13, 2022
Advisory Published
via GitHub·01:07 AM
Jan 11, 2024
Data Sourced
via Launchpad·10:46 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·12:40 AM
RemedyDescriptionSeverityAffected Software
Mar 18, 2026
Data Sourced
via Debian·01:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2018-10874?
CVE-2018-10874 is a vulnerability in Ansible that allows arbitrary code execution.
2
Which versions of Ansible are affected by CVE-2018-10874?
Versions 2.5.1+dfsg-1ubuntu0.1, 2.6.1+dfsg-1, and earlier are affected.
3
How can I fix CVE-2018-10874 in Ubuntu?
Upgrade to version 2.5.1+dfsg-1ubuntu0.1 or later of the ansible package.
4
How can I fix CVE-2018-10874 in Redhat Ansible Engine?
Upgrade to a version of Redhat Ansible Engine that is not affected by the vulnerability.
5
Is there any additional information available about CVE-2018-10874?
Yes, you can find more information at the following references: http://www.securitytracker.com/id/1041396, https://access.redhat.com/errata/RHBA-2018:3788, https://access.redhat.com/errata/RHSA-2018:2150.