Vulnerability Description
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Ansible | < 1.6.4 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- https://github.com/ansible/ansible/commit/5429b85b9f6c2e640074176f36ff05fd5e4d19PatchThird Party Advisory
- https://groups.google.com/forum/message/raw?msg=ansible-announce/ieV1vZvcTXU/5Q9Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2014-4678Third Party Advisory
- https://www.openwall.com/lists/oss-security/2014/06/26/30Mailing ListPatchThird Party Advisory
- https://www.openwall.com/lists/oss-security/2014/07/02/2Mailing ListPatchThird Party Advisory
- https://www.rapid7.com/db/vulnerabilities/freebsd-vid-2c493ac8-205e-11e5-a4a5-00Third Party Advisory
- https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2014-4678Third Party Advisory
- https://github.com/ansible/ansible/commit/5429b85b9f6c2e640074176f36ff05fd5e4d19PatchThird Party Advisory
- https://groups.google.com/forum/message/raw?msg=ansible-announce/ieV1vZvcTXU/5Q9Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2014-4678Third Party Advisory
- https://www.openwall.com/lists/oss-security/2014/06/26/30Mailing ListPatchThird Party Advisory
- https://www.openwall.com/lists/oss-security/2014/07/02/2Mailing ListPatchThird Party Advisory
- https://www.rapid7.com/db/vulnerabilities/freebsd-vid-2c493ac8-205e-11e5-a4a5-00Third Party Advisory
- https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2014-4678Third Party Advisory
FAQ
What is CVE-2014-4678?
CVE-2014-4678 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability ex...
How severe is CVE-2014-4678?
CVE-2014-4678 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2014-4678?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Ansible, Debian Debian Linux.