Описание
Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which allows remote attackers to execute arbitrary code via (1) crafted lookup('pipe') calls or (2) crafted Jinja2 data.
Ссылки
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.6.7 (исключая)
cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
EPSS
Процентиль: 89%
0.04747
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-74
Связанные уязвимости
CVSS3: 9.8
ubuntu
почти 6 лет назад
Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which allows remote attackers to execute arbitrary code via (1) crafted lookup('pipe') calls or (2) crafted Jinja2 data.
CVSS3: 9.8
debian
почти 6 лет назад
Ansible before 1.6.7 does not prevent inventory data with "{{" and "lo ...
EPSS
Процентиль: 89%
0.04747
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-74