From 2857b6e4db312be074235905b4586ed539cedb02 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 4 Sep 2024 18:52:03 +0000 Subject: [PATCH] Publish GHSA-m956-frf4-m2wr --- .../GHSA-m956-frf4-m2wr/GHSA-m956-frf4-m2wr.json | 16 ++++++++++------ 1 file changed, 10 insertions(+), 6 deletions(-) diff --git a/advisories/github-reviewed/2018/10/GHSA-m956-frf4-m2wr/GHSA-m956-frf4-m2wr.json b/advisories/github-reviewed/2018/10/GHSA-m956-frf4-m2wr/GHSA-m956-frf4-m2wr.json index 78857e2738a..a3600c076cf 100644 --- a/advisories/github-reviewed/2018/10/GHSA-m956-frf4-m2wr/GHSA-m956-frf4-m2wr.json +++ b/advisories/github-reviewed/2018/10/GHSA-m956-frf4-m2wr/GHSA-m956-frf4-m2wr.json @@ -1,17 +1,21 @@ { "schema_version": "1.4.0", "id": "GHSA-m956-frf4-m2wr", - "modified": "2022-07-15T18:33:52Z", + "modified": "2024-09-04T18:50:33Z", "published": "2018-10-10T17:22:53Z", "aliases": [ "CVE-2016-9587" ], "summary": "Ansible is vulnerable to an improper input validation in Ansible's handling of data sent from client systems", - "details": "Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.", + "details": "Ansible before versions 2.1.4.0, 2.2.1.0 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ @@ -97,6 +101,10 @@ "type": "WEB", "url": "https://security.gentoo.org/glsa/201701-77" }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20170115210655/http://www.securityfocus.com/bid/95352" + }, { "type": "WEB", "url": "https://www.exploit-db.com/exploits/41013" @@ -108,10 +116,6 @@ { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2017-0260.html" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/95352" } ], "database_specific": {