CVE-2023-5764
12.12.2023, 22:15
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | ansible | 𝑥 < 2.14.12 |
redhat | ansible | 2.15.0 ≤ 𝑥 < 2.15.7 |
redhat | ansible | 2.16.0 |
redhat | ansible | 2.16.0:beta1 |
redhat | ansible | 2.16.0:beta2 |
redhat | ansible | 2.16.0:rc1 |
fedoraproject | extra_packages_for_enterprise_linux | 8.0 |
redhat | ansible_automation_platform | 2.4 |
redhat | ansible_developer | 1.1 |
redhat | ansible_inside | 1.2 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
ansible |
| ||||||||||
ansible-core |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ansible |
| ||||||||||||||||||
ansible-core |
|
References