CVE-2018-10875: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only
- Debian Debian Linux: version 9.0 only; version 8.0 only
- Red Hat Ansible Engine: version 2.0 only; version 2.4 only; version 2.5 only; version 2.6 only
- Red Hat Ceph Storage: version 2.0 only; version 3.0 only
- Red Hat Gluster Storage: version 3.0.0 only
- Red Hat Openshift: version 3.0 only
- Red Hat Openstack: version 10 only; version 12 only; version 13 only
- Red Hat Virtualization: version 4.0 only
- Red Hat Virtualization Host: version 4.0 only
- Suse Package Hub: affected versions not specified
Published 2018-07-13. Last modified 2026-06-17.