Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-11079

Опубликовано: 11 нояб. 2024
Источник: redhat
CVSS3: 5.5

Описание

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.

Меры по смягчению последствий

To mitigate this vulnerability, avoid using the hostvars object to reference content marked as !unsafe. Ensure that all remote data from modules or lookups is properly sanitized and validated before use in playbooks. Additionally, restrict access to inventory files and Ansible playbooks to trusted users to minimize exploitation risks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10ansible-coreNot affected
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/bootc-azure-nvidia-rhel9Fix deferred
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/bootc-nvidia-rhel9Will not fix
Ansible Automation Platform Execution Environmentsansible-automation-platform/ansible-builder-rhel8FixedRHSA-2024:1077003.12.2024
Ansible Automation Platform Execution Environmentsansible-automation-platform/ansible-builder-rhel9FixedRHSA-2024:1077003.12.2024
Ansible Automation Platform Execution Environmentsansible-automation-platform/ee-29-rhel8FixedRHSA-2024:1077003.12.2024
Ansible Automation Platform Execution Environmentsansible-automation-platform/ee-minimal-rhel8FixedRHSA-2024:1077003.12.2024
Ansible Automation Platform Execution Environmentsansible-automation-platform/ee-minimal-rhel9FixedRHSA-2024:1077003.12.2024
Red Hat Ansible Automation Platform 2.5 for RHEL 8ansible-coreFixedRHSA-2024:1114516.12.2024
Red Hat Ansible Automation Platform 2.5 for RHEL 9ansible-coreFixedRHSA-2024:1114516.12.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2325171ansible-core: Unsafe Tagging Bypass via hostvars Object in Ansible-Core

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 1 года назад

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.

CVSS3: 5.5
nvd
около 1 года назад

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.

CVSS3: 5.5
debian
около 1 года назад

A flaw was found in Ansible-Core. This vulnerability allows attackers ...

CVSS3: 5.5
github
около 1 года назад

Ansible-Core vulnerable to content protections bypass

CVSS3: 5.5
fstec
около 1 года назад

Уязвимость системы управления конфигурациями Ansible, связанная с неправильной проверкой входных данных, позволяющая нарушителю обойти существующие ограничения безопасности

5.5 Medium

CVSS3