suse · CVE-2016-9587

Quick triage

Priority: high Published: 2021-05-30 13:48:01 UTC Updated: 2026-04-18 15:54:20 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-9587 severity important: SUSE including 18 source package names (ansible-10-10.6.0-1.1, ansible-11-11.11.0-1.1, …), 28 product×package rows across 13 product lines (HPE Helion OpenStack 8, SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP7, … (13 product lines)): Fixed 28.

Description:

Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.

cvelogic Threat Intelligence