Junglewise Threat Intelligence

CVE-2021-4041: PYSEC-2022-253 - A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can l

CVE-2021-4041 · Severity: low · CVSS 3.1 · Published 2022-08-24

Technologies: ansible-runner (PyPI). Vendors: PyPI.

Executive brief

A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters getting executed as host's shell command. A developer could unintentionally write code that gets executed in the host rather than the virtual environment.

Affected products

  • PyPI ansible-runner

Related threats