First published: Thu Nov 02 2023(Updated: )
A flaw was found in Ansible, where a user's controller is vulnerable to template injection when internal templating operations may errantly remove the unsafe designation from template data.
Affected Software | Affected Version | How to fix |
---|---|---|
Ansible |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2247629 is considered high due to the potential for template injection vulnerabilities.
To fix REDHAT-BUG-2247629, it is recommended to update Ansible to the latest patched version that addresses the template injection flaw.
REDHAT-BUG-2247629 specifically affects installations of Ansible that utilize internal templating operations.
If exploited, REDHAT-BUG-2247629 could allow an attacker to conduct arbitrary code execution via crafted template data.
You can determine if you are affected by REDHAT-BUG-2247629 by checking your Ansible version and reviewing its compliance against the vulnerability details.