Candidate: CVE-2014-3498 PublicDate: 2017-06-08 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3498 https://github.com/ansible/ansible/commit/8ed6350e65c82292a631f08845dfaacffe7f07f5 (v1.7.0) Description: The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands. Ubuntu-Description: It was discovered that Ansible improperly handled the output of certain commands. An attacker could use this vulnerability to execute arbitrary commands on the ansible manging host. Notes: Bugs: Priority: medium Discovered-by: Assigned-to: mikesalvatore CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_ansible: upstream_ansible: released (1.7.0+dfsg-1) precise_ansible: DNE precise/esm_ansible: DNE trusty_ansible: ignored (out of standard support) trusty/esm_ansible: needed vivid/stable-phone-overlay_ansible: DNE vivid/ubuntu-core_ansible: DNE wily_ansible: not-affected (1.9.2+dfsg-2) xenial_ansible: not-affected yakkety_ansible: not-affected zesty_ansible: not-affected artful_ansible: not-affected bionic_ansible: not-affected cosmic_ansible: not-affected disco_ansible: not-affected eoan_ansible: not-affected focal_ansible: not-affected groovy_ansible: not-affected hirsute_ansible: not-affected impish_ansible: not-affected jammy_ansible: not-affected devel_ansible: not-affected