Логотип exploitDog
bind:CVE-2017-7481
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-7481

Количество 6

Количество 6

ubuntu логотип

CVE-2017-7481

больше 7 лет назад

Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not evaluated.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2017-7481

почти 9 лет назад

Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not evaluated.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2017-7481

больше 7 лет назад

Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not evaluated.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-7481

больше 7 лет назад

Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark loo ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-w578-j992-554x

больше 7 лет назад

Ansible fails to properly mark lookup-plugin results as unsafe

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2020-02914

почти 9 лет назад

Уязвимость системы управления конфигурациями Ansible, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-7481

Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not evaluated.

CVSS3: 9.8
2%
Низкий
больше 7 лет назад
redhat логотип
CVE-2017-7481

Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not evaluated.

CVSS3: 5.3
2%
Низкий
почти 9 лет назад
nvd логотип
CVE-2017-7481

Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not evaluated.

CVSS3: 9.8
2%
Низкий
больше 7 лет назад
debian логотип
CVE-2017-7481

Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark loo ...

CVSS3: 9.8
2%
Низкий
больше 7 лет назад
github логотип
GHSA-w578-j992-554x

Ansible fails to properly mark lookup-plugin results as unsafe

CVSS3: 9.8
2%
Низкий
больше 7 лет назад
fstec логотип
BDU:2020-02914

Уязвимость системы управления конфигурациями Ansible, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.3
2%
Низкий
почти 9 лет назад

Уязвимостей на страницу