—
PYSEC-2018-41
상세
Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not evaluated.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
PyPI / ansible
최초 영향 버전:
0 수정 버전: ed56f51f185a1ffd7ea57130d260098686fcc7c2 수정
pip install --upgrade 'ansible>=ed56f51f185a1ffd7ea57130d260098686fcc7c2' 참고
- https://github.com/ansible/ansible/commit/ed56f51f185a1ffd7ea57130d260098686fcc7c2 [FIX]
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7481 [REPORT]
- https://access.redhat.com/errata/RHSA-2017:2524 [ADVISORY]
- https://access.redhat.com/errata/RHSA-2017:1599 [ADVISORY]
- https://access.redhat.com/errata/RHSA-2017:1499 [ADVISORY]
- https://access.redhat.com/errata/RHSA-2017:1476 [ADVISORY]
- https://access.redhat.com/errata/RHSA-2017:1334 [ADVISORY]
- https://access.redhat.com/errata/RHSA-2017:1244 [ADVISORY]
- http://www.securityfocus.com/bid/98492 [WEB]
- https://usn.ubuntu.com/4072-1/ [WEB]
- https://lists.debian.org/debian-lts-announce/2021/01/msg00023.html [WEB]
- https://github.com/advisories/GHSA-w578-j992-554x [ADVISORY]