CVE-2016-8614

high

Description

A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.

References

https://github.com/ansible/ansible-modules-core/pull/5357

https://github.com/ansible/ansible-modules-core/pull/5353

http://www.securityfocus.com/bid/94108

Details

Source: Mitre, NVD

Published: 2018-07-31

Updated: 2023-11-07

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Severity: High