Server side template injection In github.com/ansible-semaphore/semaphore
Description
Code injection in ansible semaphore An issue in ansible semaphore v.2.8.90 allows a remote attacker to execute arbitrary code via a crafted payload to the extra variables parameter.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version |
|---|---|---|
go |
Aliases
1. 2. 3. 4.
References
1. 2.