← Back

CVE-2019-14905

nvd nist
Published: Mar 31, 2020Modified: Jun 17, 2026

JSON object

Loading...
5.6
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
Exploitability: 0.8 / Impact: 4.7
Source: NVD

Description

A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.

Affected (10)

5 products
Ansible Engine
Ansible Tower
Ceph Storage
Cloudforms Management Engine
Openstack
1 product
Fedora
2 products
Backports Sle
Leap
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
From 2.7.0 to 2.7.16
From 2.8.0 to 2.8.8
From 2.9.0 to 2.9.3
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.0.0
Version 3.0
Version 5.0
Version 13
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 30
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.0 sp1
Version 15.1

References (12)

Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
PatchVendor Advisory
Source: secalert@redhat.com
PatchVendor Advisory
Source: secalert@redhat.com
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory

Timeline

No history available yet.