CVE-2023-5764

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-5764
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-5764.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-5764
Aliases
Related
Published
2023-12-12T22:15:22Z
Modified
2024-11-02T04:52:29.551971Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.

References

Affected packages

Debian:11 / ansible

Package

Name
ansible
Purl
pkg:deb/debian/ansible?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.10.7+merged+base+2.10.8+dfsg-1
2.10.7+merged+base+2.10.17+dfsg-0+deb11u1

4.*

4.6.0-1

5.*

5.4.0-1
5.5.0-1

6.*

6.3.0+dfsg-1
6.4.0+dfsg-1

7.*

7.0.0+dfsg-1
7.0.0+dfsg-2
7.1.0+dfsg-1
7.2.0+dfsg-2
7.3.0+dfsg-1
7.7.0+dfsg-1
7.7.0+dfsg-2
7.7.0+dfsg-3

9.*

9.4.0+dfsg-1
9.5.1+dfsg-1

10.*

10.0.0+dfsg-1
10.0.1+dfsg-1
10.1.0+dfsg-1
10.5.0+dfsg-1
10.5.0+dfsg-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / ansible

Package

Name
ansible
Purl
pkg:deb/debian/ansible?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / ansible

Package

Name
ansible
Purl
pkg:deb/debian/ansible?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / ansible-core

Package

Name
ansible-core
Purl
pkg:deb/debian/ansible-core?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.14.16-0+deb12u1

Affected versions

2.*

2.14.3-1
2.14.6-1
2.14.7-1
2.14.8-1
2.14.9-1
2.14.9-2
2.14.10-1
2.14.11-1
2.14.11-2
2.14.13-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / ansible-core

Package

Name
ansible-core
Purl
pkg:deb/debian/ansible-core?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.14.13-1

Affected versions

2.*

2.14.3-1
2.14.6-1
2.14.7-1
2.14.8-1
2.14.9-1
2.14.9-2
2.14.10-1
2.14.11-1
2.14.11-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}