id: PYSEC-2020-198 details: Ansible prior to 1.5.4 mishandles the evaluation of some strings. affected: - package: name: ansible ecosystem: PyPI purl: pkg:pypi/ansible ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 1.5.4 versions: - "1.0" - "1.1" - "1.2" - 1.2.1 - 1.2.2 - 1.2.3 - 1.3.0 - 1.3.1 - 1.3.2 - 1.3.3 - 1.3.4 - "1.4" - 1.4.1 - 1.4.2 - 1.4.3 - 1.4.4 - 1.4.5 - "1.5" - 1.5.1 - 1.5.2 - 1.5.3 references: - type: WEB url: https://groups.google.com/forum/#!searchin/ansible-project/1.5.4/ansible-project/MUQxiKwSQDc/id6aVaawVboJ - type: ADVISORY url: https://github.com/advisories/GHSA-49m5-2838-q2rv aliases: - CVE-2014-2686 - GHSA-49m5-2838-q2rv modified: "2021-07-02T02:41:33.018970Z" published: "2020-01-09T13:15:00Z"