CVE-2023-5764
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/12/2023
Last modified:
16/09/2024
Description
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:* | 2.14.12 (excluding) | |
| cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:* | 2.15.0 (including) | 2.15.7 (excluding) |
| cpe:2.3:a:redhat:ansible:2.16.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:ansible:2.16.0:beta1:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:ansible:2.16.0:beta2:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:ansible:2.16.0:rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:8.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* | ||
| cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:ansible_automation_platform:2.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:ansible_developer:1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:ansible_inside:1.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



