ansible-runner@2.1.0.0a2 vulnerabilities

"Consistent Ansible Python API and CLI with container and process isolation runtime capabilities"

  • latest version

    2.4.0

  • latest non vulnerable version

  • first published

    6 years ago

  • latest version published

    9 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the ansible-runner package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Improper Input Validation

    ansible-runner is a tool that helps when interfacing with Ansible directly or as part of another system whether that be through a container image interface, as a standalone tool, or as a Python module that can be imported.

    Affected versions of this package are vulnerable to Improper Input Validation while calling ansible_runner.interface.run_command, due to improper escaping of shell command where the parameters get executed as host's shell command. A developer could unintentionally write code that gets executed in the host rather than the virtual environment.

    How to fix Improper Input Validation?

    Upgrade ansible-runner to version 2.1.0 or higher.

    [,2.1.0)