CVE-2014-4966 describes a critical arbitrary code execution vulnerability in Ansible versions prior to 1.6.7. This flaw allows remote attackers to execute arbitrary code by injecting specially crafted Jinja2 data or lookup('pipe') calls into inventory or remote data. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While no public exploit intelligence (Metasploit, Nuclei, ExploitDB) is currently available, and community discussion and media coverage are minimal, the high FAUCET Risk Score of 84/100 indicates significant potential impact if exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.7CPE matchmatch criteria | cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.