CVE-2014-4967: Red Hat Ansible

Critical severity, CVSS 9.8. EPSS: 3.6% chance of exploitation in the next 30 days.

Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansible managed host and providing a crafted fact, as demonstrated by a fact with (1) a trailing " src=" clause, (2) a trailing " temp=" clause, or (3) a trailing " validate=" clause accompanied by a shell command.

Affected products

  • Red Hat Ansible: before 1.6.7 (fixed in 1.6.7)

Published 2020-02-18. Last modified 2026-06-17.