7.8

CVE-2023-5764

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.

Data is provided by the National Vulnerability Database (NVD)
RedhatAnsible Version < 2.14.12
RedhatAnsible Version >= 2.15.0 < 2.15.7
RedhatAnsible Version2.16.0 Update-
RedhatAnsible Version2.16.0 Updatebeta1
RedhatAnsible Version2.16.0 Updatebeta2
RedhatAnsible Version2.16.0 Updaterc1
FedoraprojectFedora Version38
FedoraprojectFedora Version39
RedhatAnsible Automation Platform Version2.4
   RedhatEnterprise Linux Version8.0
   RedhatEnterprise Linux Version9.0
RedhatAnsible Developer Version1.1
   RedhatEnterprise Linux Version8.0
   RedhatEnterprise Linux Version9.0
RedhatAnsible Inside Version1.2
   RedhatEnterprise Linux Version8.0
   RedhatEnterprise Linux Version9.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.225
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
secalert@redhat.com 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine

The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.