Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-5764

Опубликовано: 12 дек. 2023
Источник: debian

Описание

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ansible-corefixed2.14.13-1package
ansible-corefixed2.14.16-0+deb12u1bookwormpackage
ansiblefixed5.4.0-1package
ansiblefixed2.10.7+merged+base+2.10.17+dfsg-0+deb11u1bullseyepackage

Примечания

  • ansible-core was split off from src:ansible with 4.6.0-1 in experimental/5.4.0-1 in sid

  • https://bugzilla.redhat.com/show_bug.cgi?id=2247629

  • https://github.com/ansible/ansible/pull/82293 (stable-2.16)

  • https://github.com/ansible/ansible/pull/82294 (stable-2.15)

  • https://github.com/ansible/ansible/pull/82295 (stable-2.14)

  • https://github.com/ansible/ansible/commit/7239d2d371bc6e274cbb7314e01431adce6ae25a (v2.14.12rc1)

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 2 лет назад

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.

CVSS3: 7.1
redhat
больше 2 лет назад

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.

CVSS3: 7.1
nvd
около 2 лет назад

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.

CVSS3: 7.8
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 6.6
github
около 2 лет назад

Ansible template injection vulnerability