Advisory Published

USN-6846-3: Ansible regression

First published: Thu Feb 13 2025(Updated: )

USN-6846-1 fixed vulnerabilities in ansible. The update introduced a regression in ansible. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that Ansible incorrectly handled certain inputs when using tower_callback parameter. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2022-3697) It was discovered that Ansible incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to perform a Template Injection. (CVE-2023-5764)

Affected SoftwareAffected VersionHow to fix
All of
ubuntu/ansible<2.5.1+dfsg-1ubuntu0.1+esm4
2.5.1+dfsg-1ubuntu0.1+esm4
Ubuntu=18.04
All of
ubuntu/ansible<2.0.0.2-2ubuntu1.3+esm4
2.0.0.2-2ubuntu1.3+esm4
Ubuntu=16.04

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of USN-6846-3?

    The severity of USN-6846-3 is considered moderate as it addresses a regression issue in Ansible that could impact its functionality.

  • How do I fix USN-6846-3?

    To fix USN-6846-3, update your Ansible package to the recommended versions specified in the advisory.

  • What vulnerabilities does USN-6846-3 address?

    USN-6846-3 addresses a regression introduced in previous updates related to input handling in Ansible.

  • Which versions of Ansible are affected by USN-6846-3?

    USN-6846-3 affects Ansible versions prior to 2.5.1+dfsg-1ubuntu0.1+esm4 for Ubuntu 18.04 and those before 2.0.0.2-2ubuntu1.3+esm4 for Ubuntu 16.04.

  • Can USN-6846-3 lead to any security risks?

    While USN-6846-3 primarily addresses functional issues, it's crucial to apply the patch to ensure stability and avoid potential indirect security risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203