Home

Description

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.

PUBLISHED Reserved 2023-10-25 | Published 2023-12-12 | Updated 2025-11-20 | Assigner redhat




HIGH: 7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Problem types

Improper Neutralization of Special Elements Used in a Template Engine

Product status

Default status
affected

1:2.15.8-1.el8ap (rpm) before *
unaffected

Default status
affected

1:2.15.8-1.el8ap (rpm) before *
unaffected

Default status
affected

1:2.15.8-1.el9ap (rpm) before *
unaffected

Default status
affected

1:2.15.8-1.el9ap (rpm) before *
unaffected

Timeline

2023-11-02:Reported to Red Hat.
2023-11-02:Made public.

References

access.redhat.com/errata/RHSA-2023:7773 (RHSA-2023:7773) vendor-advisory

access.redhat.com/security/cve/CVE-2023-5764 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2247629 (RHBZ#2247629) issue-tracking

lists.fedoraproject.org/...X7Q6CHPVCHMZS5M7V22GOKFSXZAQ24EU/

security.netapp.com/advisory/ntap-20241025-0001/

access.redhat.com/errata/RHSA-2023:7773 (RHSA-2023:7773) vendor-advisory

access.redhat.com/security/cve/CVE-2023-5764 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2247629 (RHBZ#2247629) issue-tracking

cve.org (CVE-2023-5764)

nvd.nist.gov (CVE-2023-5764)

Download JSON