Vulnerabilities > CVE-2023-39059 - Unspecified vulnerability in Ansible-Semaphore Ansible Semaphore 2.8.90
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
An issue in ansible semaphore v.2.8.90 allows a remote attacker to execute arbitrary code via a crafted payload to the extra variables parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- https://gist.github.com/Alevsk/1757da24c5fb8db735d392fd4146ca3a
- https://gist.github.com/Alevsk/1757da24c5fb8db735d392fd4146ca3a
- https://www.alevsk.com/2023/07/a-quick-story-of-security-pitfalls-with-execcommand-in-software-integrations/
- https://www.alevsk.com/2023/07/a-quick-story-of-security-pitfalls-with-execcommand-in-software-integrations/