CVE-2015-6240

Aliases:GHSA-wwwh-47wp-m522PYSEC-2017-3
Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 07 Jun 2017, 20:00
Last modified:06 Aug 2024, 07:15

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
v3.0 (nvd)
EPSS Score
0.04% LOW
0% probability +0.01%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

07 Jun 2017, 20:00
Published
Vulnerability first disclosed
06 Aug 2024, 07:15
Last Modified
Vulnerability information updated

Description

The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environment via a symlink attack.

CVSS Metrics

  • v4.0HIGHScore: 8.5CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  • v3.0HIGHScore: 7.8CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 0.04% Percentile: 13%

Techniques & Countermeasures

  • CWE-59Improper Link Resolution Before File Access ('Link Following')

    The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Affected Systems

  • PyPIansible

    < 952166f48eb0f5797b75b160fd156bbe1e8fc647 | < 1.9.2

  • redhatansible

    ≤ 1.9.1

References (8)