Security Advisory

CVE-2018-10874

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-07-02 13:00:00
Last updated 2024-08-05 07:46:47
Assigner redhat
CVSS score 7.8
State PUBLISHED

Description

In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.