Description
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
Problem types
Improper Neutralization of Special Elements Used in a Template Engine
Product status
1:2.15.8-1.el8ap (rpm) before *
1:2.15.8-1.el8ap (rpm) before *
1:2.15.8-1.el9ap (rpm) before *
1:2.15.8-1.el9ap (rpm) before *
Timeline
| 2023-11-02: | Reported to Red Hat. |
| 2023-11-02: | Made public. |
References
access.redhat.com/errata/RHSA-2023:7773 (RHSA-2023:7773)
access.redhat.com/security/cve/CVE-2023-5764
bugzilla.redhat.com/show_bug.cgi?id=2247629 (RHBZ#2247629)
lists.fedoraproject.org/...X7Q6CHPVCHMZS5M7V22GOKFSXZAQ24EU/
security.netapp.com/advisory/ntap-20241025-0001/
access.redhat.com/errata/RHSA-2023:7773 (RHSA-2023:7773)
access.redhat.com/security/cve/CVE-2023-5764
bugzilla.redhat.com/show_bug.cgi?id=2247629 (RHBZ#2247629)