Ansible apt_key module does not properly verify key fingerprint
High severity
GitHub Reviewed
Published
Oct 10, 2018
to the GitHub Advisory Database
•
Updated Sep 3, 2024
Description
Published to the GitHub Advisory Database
Oct 10, 2018
Reviewed
Jun 16, 2020
Last updated
Sep 3, 2024
A flaw was found in Ansible before version 2.2.0.0. The
apt_keymodule does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.References