—
PYSEC-2020-204
Quick fix
PYSEC-2020-204 — ansible: upgrade to the fixed version with the command below.
pip install --upgrade 'ansible>=62a1295a3e08cb6c3e9f1b2a1e6e5dcaeab32527'Details
Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which allows remote attackers to execute arbitrary code via (1) crafted lookup('pipe') calls or (2) crafted Jinja2 data.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/ansible
Introduced in:
0Fixed in: 62a1295a3e08cb6c3e9f1b2a1e6e5dcaeab32527Fix
pip install --upgrade 'ansible>=62a1295a3e08cb6c3e9f1b2a1e6e5dcaeab32527'