CVE-2016-8614

A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:59

Type Values Removed Values Added
CVSS v2 : 5.0
v3 : 7.5
v2 : 5.0
v3 : 6.3
References () http://www.securityfocus.com/bid/94108 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/94108 - Third Party Advisory, VDB Entry
References () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8614 - Exploit, Issue Tracking, Patch, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8614 - Exploit, Issue Tracking, Patch, Third Party Advisory
References () https://github.com/ansible/ansible-modules-core/issues/5237 - Exploit, Third Party Advisory () https://github.com/ansible/ansible-modules-core/issues/5237 - Exploit, Third Party Advisory
References () https://github.com/ansible/ansible-modules-core/pull/5353 - Third Party Advisory () https://github.com/ansible/ansible-modules-core/pull/5353 - Third Party Advisory
References () https://github.com/ansible/ansible-modules-core/pull/5357 - Third Party Advisory () https://github.com/ansible/ansible-modules-core/pull/5357 - Third Party Advisory

Information

Published : 2018-07-31 21:29

Updated : 2024-11-21 02:59


NVD link : CVE-2016-8614

Mitre link : CVE-2016-8614

CVE.ORG link : CVE-2016-8614


JSON object : View

Products Affected

redhat

  • ansible
CWE
CWE-358

Improperly Implemented Security Check for Standard

CWE-320

Key Management Errors