3 ms·
Can anyone explain in simple terms what is this about? Exploit found in Ansible? Should we all update asap? I couldn't understand from article or discussion.
by romanr 10y ago
Can anyone explain in simple terms what is this about? Exploit found in Ansible? Should we all update asap?
I couldn't understand from article or discussion.
- deleted 10y ago[deleted]
- grey-area 10y agoAnsible sends commands to servers, but asks them for certain data first (facts). If one of your servers is compromised, this is a vulnerability in the ansible client that lets that bad server take over your local computer and your other servers when you connect to it by sending you bad facts. So it's pretty serious.
- mverwijs 10y agoPuppet uses facter and chef ohai to achieve te same thing. Could they be exploited in similar fashion?
- Piatro 10y agoUnfortunately versions 2.1.4 and 2.2.1 are still in release candidate phase so package managers such as Homebrew are still using vulnerable releases, as far as I can tell.