VDB
KO
MEDIUM 6.6

GHSA-7j69-qfc3-2fq9

Ansible template injection vulnerability

Details

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / ansible-core
Introduced in: 2.16.0 Fixed in: 2.16.1
Fix pip install --upgrade 'ansible-core>=2.16.1'
PyPI / ansible-core
Introduced in: 2.15.0 Fixed in: 2.15.8
Fix pip install --upgrade 'ansible-core>=2.15.8'
PyPI / ansible-core
Introduced in: 0 Fixed in: 2.14.12
Fix pip install --upgrade 'ansible-core>=2.14.12'

References