Server side template injection In ansible-core
Description
Ansible template injection vulnerability A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 2.16.1, 2.15.8, 2.14.12 | ||
debian 11 | 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1 | ||
debian 12 | 5.4.0-1 | ||
debian 13 | 5.4.0-1 | ||
debian 14 | 5.4.0-1 | ||
debian 12 | 2.14.16-0+deb12u1 | ||
debian 13 | 2.14.13-1 | ||
debian 14 | 2.14.13-1 | ||
pypi | 3.0.0 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8.
References
1. 2. 3. 4. 5. 6. 7.