High severityNVD Advisory· Published Aug 12, 2015· Updated Jun 17, 2026
CVE-2015-3908
CVE-2015-3908
Description
Ansible before 1.9.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ansiblePyPI | < 1.9.2 | 1.9.2 |
Affected products
8- ghsa-coords7 versionspkg:pypi/ansiblepkg:rpm/opensuse/ansible-10&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ansible-11&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ansible-12&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ansible-13&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ansible-9&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ansible&distro=openSUSE%20Tumbleweed
< 1.9.2+ 6 more
- (no CPE)range: < 1.9.2
- (no CPE)range: < 10.6.0-1.1
- (no CPE)range: < 11.11.0-1.1
- (no CPE)range: < 12.2.0-1.1
- (no CPE)range: < 13.7.0-1.1
- (no CPE)range: < 9.8.0-1.1
- (no CPE)range: < 2.2.0.0-1.1
Patches
Vulnerability mechanics
References
8- lists.opensuse.org/opensuse-updates/2015-07/msg00051.htmlnvdThird Party AdvisoryWEB
- lists.opensuse.org/opensuse-updates/2015-08/msg00029.htmlnvdThird Party AdvisoryWEB
- www.ansible.com/securitynvdVendor AdvisoryWEB
- github.com/advisories/GHSA-w64c-pxjj-h866ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2015-3908ghsaADVISORY
- www.openwall.com/lists/oss-security/2015/07/14/4nvdMailing ListWEB
- github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2015-1.yamlghsaWEB
- lists.debian.org/debian-lts-announce/2019/09/msg00016.htmlnvdWEB
News mentions
0No linked articles in our index yet.