Safety vulnerability ID: 25617
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Ansible 1.5.4 includes a fix for CVE-2014-4657: The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.
Latest version: 11.1.0
Radically simple IT automation
- Security fix for safe_eval, which further hardens the checking of the evaluation function.
- Changing order of variable precedence for system facts, to ensure that inventory variables take precedence over any facts that may be set on a host.
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application