Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-5764


A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.


Published

2023-12-12T22:15:22.747

Last Modified

2024-11-21T08:42:26.410

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.1 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-1336
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redhat ansible < 2.14.12 Yes
Application redhat ansible < 2.15.7 Yes
Application redhat ansible 2.16.0 Yes
Application redhat ansible 2.16.0 Yes
Application redhat ansible 2.16.0 Yes
Application redhat ansible 2.16.0 Yes
Application fedoraproject extra_packages_for_enterprise_linux 8.0 Yes
Operating System fedoraproject fedora 38 Yes
Operating System fedoraproject fedora 39 Yes
Application redhat ansible_automation_platform 2.4 Yes
Application redhat ansible_developer 1.1 Yes
Application redhat ansible_inside 1.2 Yes
Operating System redhat enterprise_linux 8.0 No
Operating System redhat enterprise_linux 9.0 No

References