{"id":"CVE-2014-3498","aliases":["GHSA-4cvm-5776-jx9f","PYSEC-2017-2"],"url":"https://o3.security/vulnerability/CVE-2014-3498","summary":"Ansible Arbitrary Code Execution","details":"The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands.","published":"2017-06-08T18:29:00Z","modified":"2026-04-10T03:43:45.855911Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"ansible","fixedVersion":"1.6.6"}],"fix":{"url":"https://github.com/ansible/ansible/commit/8ed6350e65c82292a631f08845dfaacffe7f07f5","label":"ansible/ansible@8ed6350"},"references":[{"type":"ADVISORY","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1335551"},{"type":"ADVISORY","url":"https://github.com/ansible/ansible/commit/8ed6350e65c82292a631f08845dfaacffe7f07f5"},{"type":"FIX","url":"https://github.com/ansible/ansible/commit/8ed6350e65c82292a631f08845dfaacffe7f07f5"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1335551"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T03:43:45.855911Z"}}