Red Hat Security Advisory 2017-1499-01

Discussion in 'News Aggregator' started by Packet Storm, 20 Jun 2017.

  1. Packet Storm

    Packet Storm Guest

    Red Hat Security Advisory 2017-1499-01 - Ansible is a simple model-driven configuration management, multi-node deployment, and remote-task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically. Security Fix: An input validation vulnerability was found in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible, and the ability to send facts back to the Ansible server, could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.

    Continue reading...
     

Share This Page

Loading...