A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade ansible-testUpgrade ansible-core | Feb 17, 2025 | Dec 12, 2023 |
| Debian | — | Upgrade ansibleUpgrade ansible-core | Jul 30, 2024 | Dec 12, 2023 |
| Suse | — | Upgrade ansible-testUpgrade ansibleUpgrade ansible-doc | May 7, 2024 | Dec 12, 2023 |
| Ubuntu | — | Upgrade ansible (Ubuntu Pro) | Jun 26, 2024 | Dec 12, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 12, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub