CVE-2018-10875: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only
  • Debian Debian Linux: version 9.0 only; version 8.0 only
  • Red Hat Ansible Engine: version 2.0 only; version 2.4 only; version 2.5 only; version 2.6 only
  • Red Hat Ceph Storage: version 2.0 only; version 3.0 only
  • Red Hat Gluster Storage: version 3.0.0 only
  • Red Hat Openshift: version 3.0 only
  • Red Hat Openstack: version 10 only; version 12 only; version 13 only
  • Red Hat Virtualization: version 4.0 only
  • Red Hat Virtualization Host: version 4.0 only
  • Suse Package Hub: affected versions not specified

Published 2018-07-13. Last modified 2026-06-17.