CVE Database
/

CVE-2021-4041

Back to search

CVE-2021-4041

Published: Aug 24, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters getting executed as host's shell command. A developer could unintentionally write code that gets executed in the host rather than the virtual environment.

VendorProductVersions

n/a

ansible-runner

affected
Fixed in ansible-runner 2.1.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now