CVE-2016-8614

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/07/2018
Last modified:
07/11/2023

Description

A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:* 2.2.0 (excluding)