Server side template injection In ansible-core
Description
ansible-core: Argument injection in ansible-galaxy role install leads to arbitrary code execution A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rpm rhel10.0 | 1:2.16.14-1.el10_0.1 | ||
rpm rhel9.6 | 1:2.14.18-1.el9_6.1 | ||
debian 14 | 2.21.1~rc1-1 | ||
debian 13 | 5.4.0-1 | ||
debian 12 | - | ||
debian 14 | 5.4.0-1 | ||
debian 12 | 5.4.0-1 | ||
debian 13 | 2.19.11-0+deb13u1 | ||
rpm rhel10 | 1:2.16.16-2.el10_2.1 | ||
rpm rhel8 | 0:2.16.3-4.el8_10 |
1-10 of 12
10
Aliases
References