Ansible template injection vulnerability
Moderate severity
GitHub Reviewed
Published
Dec 13, 2023
to the GitHub Advisory Database
•
Updated Sep 16, 2024
Package
Affected versions
>= 2.16.0, < 2.16.1
>= 2.15.0, < 2.15.8
< 2.14.12
Patched versions
2.16.1
2.15.8
2.14.12
Description
Published by the National Vulnerability Database
Dec 12, 2023
Published to the GitHub Advisory Database
Dec 13, 2023
Reviewed
Dec 20, 2023
Last updated
Sep 16, 2024
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
References