CVE Published: 31/03/2020 |
CVE Updated: 05/08/2024 |
CVE Year: 2019 Source: redhat |
Vendor: Red Hat |
Product: Ansible Status : PUBLISHED
CVE-2019-14905 Description
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible\'s nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.