{"id":"CVE-2014-2686","aliases":["GHSA-49m5-2838-q2rv","PYSEC-2020-198"],"url":"https://o3.security/vulnerability/CVE-2014-2686","summary":"Ansible unsafe evaluation of some strings","details":"Ansible prior to 1.5.4 mishandles the evaluation of some strings.","published":"2020-01-09T13:15:10Z","modified":"2026-04-10T03:43:43.002431Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"ansible","fixedVersion":"1.5.4"}],"fix":{"url":"https://github.com/ansible/ansible/commit/998793fd0ab55705d57527a38cee5e83f535974c","label":"ansible/ansible@998793f"},"references":[{"type":"WEB","url":"https://groups.google.com/forum/#%21searchin/ansible-project/1.5.4/ansible-project/MUQxiKwSQDc/id6aVaawVboJ"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-2686"},{"type":"WEB","url":"https://github.com/ansible/ansible/commit/998793fd0ab55705d57527a38cee5e83f535974c"},{"type":"PACKAGE","url":"https://github.com/ansible/ansible"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2020-198.yaml"},{"type":"WEB","url":"https://groups.google.com/forum/#!searchin/ansible-project/1.5.4/ansible-project/MUQxiKwSQDc/id6aVaawVboJ"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T03:43:43.002431Z"}}