Vulnerability Description
In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Ansible Engine | 2.0 |
| Redhat | Openstack | 10 |
| Redhat | Virtualization | 4.0 |
| Redhat | Virtualization Host | 4.0 |
Related Weaknesses (CWE)
References
- http://www.securitytracker.com/id/1041396Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHBA-2018:3788Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2150Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2151Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2152Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2166Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2321Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2585Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0054Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10874Issue TrackingVendor Advisory
- https://usn.ubuntu.com/4072-1/
- http://www.securitytracker.com/id/1041396Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHBA-2018:3788Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2150Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2151Vendor Advisory
FAQ
What is CVE-2018-10874?
CVE-2018-10874 is a vulnerability with a CVSS score of 7.8 (HIGH). In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.
How severe is CVE-2018-10874?
CVE-2018-10874 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10874?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Ansible Engine, Redhat Openstack, Redhat Virtualization, Redhat Virtualization Host.