CVE Vulnerabilities

CVE-2015-3908

Insufficient Verification of Data Authenticity

Published: Aug 12, 2015 | Modified: Sep 16, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
7.6 IMPORTANT
AV:N/AC:H/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM

Ansible before 1.9.2 does not verify that the server hostname matches a domain name in the subjects Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

Name Vendor Start Version End Version
Ansible Redhat * 1.9.1 (including)
Ansible Ubuntu esm-infra-legacy/trusty *
Ansible Ubuntu trusty *
Ansible Ubuntu trusty/esm *
Ansible Ubuntu upstream *
Ansible Ubuntu utopic *
Ansible Ubuntu vivid *

References