In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| ansible(PyPI) | 0 | 2.4.6.0 | N/A |
| ansible(PyPI) | 2.5 | 2.5.6 | N/A |
| ansible(PyPI) | 2.6 | 2.6.1 | N/A |
CVSS Metrics