LWN.net Logo

ansible: man in the middle attack

Package(s):ansible CVE #(s):CVE-2013-2233
Created:July 15, 2013 Updated:July 17, 2013
Description: From the Red Hat bugzilla:

A security flaw was found in the way Ansible, a SSH-based configuration management, deployment, and task execution system, performed remote server's SSH host key management (previously ability to store known SSH server's host keys to local cache was not supported). A remote attacker could use this flaw to conduct man-in-the-middle (MiTM) attacks against the Ansible task execution system user.

Alerts:
Fedora FEDORA-2013-12389 2013-07-15
Fedora FEDORA-2013-12400 2013-07-15
Fedora FEDORA-2013-12394 2013-07-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds