Описание
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| ansible-core | fixed | 2.14.13-1 | package | |
| ansible-core | fixed | 2.14.16-0+deb12u1 | bookworm | package |
| ansible | fixed | 5.4.0-1 | package | |
| ansible | fixed | 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1 | bullseye | package |
Примечания
ansible-core was split off from src:ansible with 4.6.0-1 in experimental/5.4.0-1 in sid
https://bugzilla.redhat.com/show_bug.cgi?id=2247629
https://github.com/ansible/ansible/pull/82293 (stable-2.16)
https://github.com/ansible/ansible/pull/82294 (stable-2.15)
https://github.com/ansible/ansible/pull/82295 (stable-2.14)
https://github.com/ansible/ansible/commit/7239d2d371bc6e274cbb7314e01431adce6ae25a (v2.14.12rc1)
Связанные уязвимости
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.