CVE-2016-8614
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/07/2018
Last modified:
07/11/2023
Description
A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:* | 2.2.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



