Skip to content

Ansible is vulnerable to an improper input validation in Ansible's handling of data sent from client systems

High severity GitHub Reviewed Published Oct 10, 2018 to the GitHub Advisory Database • Updated Sep 4, 2024

Package

pip ansible (pip)

Affected versions

<= 2.1.3.0
= 2.2.0.0

Patched versions

2.1.4.0
2.2.1.0

Description

Published by the National Vulnerability Database Apr 24, 2018
Published to the GitHub Advisory Database Oct 10, 2018
Reviewed Jun 16, 2020
Last updated Sep 4, 2024

Severity

High

EPSS score

1.711%
(88th percentile)

Weaknesses

CVE ID

CVE-2016-9587

GHSA ID

GHSA-m956-frf4-m2wr

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.