Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-99w6-3xph-cx78

Опубликовано: 12 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS4: 1.2
CVSS3: 5.5

Описание

Ansible-Core vulnerable to content protections bypass

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.

Пакеты

Наименование

ansible-core

pip
Затронутые версииВерсия исправления

>= 2.18.0b1, < 2.18.1rc1

2.18.1rc1

Наименование

ansible-core

pip
Затронутые версииВерсия исправления

>= 2.17.0b1, < 2.17.7rc1

2.17.7rc1

Наименование

ansible-core

pip
Затронутые версииВерсия исправления

< 2.16.14rc1

2.16.14rc1

EPSS

Процентиль: 60%
0.00393
Низкий

1.2 Low

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 1 года назад

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.

CVSS3: 5.5
redhat
около 1 года назад

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.

CVSS3: 5.5
nvd
около 1 года назад

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.

CVSS3: 5.5
debian
около 1 года назад

A flaw was found in Ansible-Core. This vulnerability allows attackers ...

CVSS3: 5.5
fstec
около 1 года назад

Уязвимость системы управления конфигурациями Ansible, связанная с неправильной проверкой входных данных, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 60%
0.00393
Низкий

1.2 Low

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-20