A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
2023-12-12T22:15:22.747
2024-11-21T08:42:26.410
Modified
CVSSv3.1: 7.1 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | ansible | < 2.14.12 | Yes |
Application | redhat | ansible | < 2.15.7 | Yes |
Application | redhat | ansible | 2.16.0 | Yes |
Application | redhat | ansible | 2.16.0 | Yes |
Application | redhat | ansible | 2.16.0 | Yes |
Application | redhat | ansible | 2.16.0 | Yes |
Application | fedoraproject | extra_packages_for_enterprise_linux | 8.0 | Yes |
Operating System | fedoraproject | fedora | 38 | Yes |
Operating System | fedoraproject | fedora | 39 | Yes |
Application | redhat | ansible_automation_platform | 2.4 | Yes |
Application | redhat | ansible_developer | 1.1 | Yes |
Application | redhat | ansible_inside | 1.2 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | No |
Operating System | redhat | enterprise_linux | 9.0 | No |