Ansible apt_key module does not properly verify key fingerprint
High severity
GitHub Reviewed
Published
Oct 10, 2018
to the GitHub Advisory Database
•
Updated Sep 3, 2024
Description
Published to the GitHub Advisory Database
Oct 10, 2018
Reviewed
Jun 16, 2020
Last updated
Sep 3, 2024
A flaw was found in Ansible before version 2.2.0.0. The
apt_key
module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.References