Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7j69-qfc3-2fq9

Опубликовано: 13 дек. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.6

Описание

Ansible template injection vulnerability

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.

Пакеты

Наименование

ansible-core

pip
Затронутые версииВерсия исправления

>= 2.16.0, < 2.16.1

2.16.1

Наименование

ansible-core

pip
Затронутые версииВерсия исправления

>= 2.15.0, < 2.15.8

2.15.8

Наименование

ansible-core

pip
Затронутые версииВерсия исправления

< 2.14.12

2.14.12

EPSS

Процентиль: 22%
0.00071
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-1336

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 2 лет назад

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.

CVSS3: 7.1
redhat
больше 2 лет назад

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.

CVSS3: 7.1
nvd
около 2 лет назад

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.

CVSS3: 7.8
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 7.1
debian
около 2 лет назад

A template injection flaw was found in Ansible where a user's controll ...

EPSS

Процентиль: 22%
0.00071
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-1336