CVE-2023-5764

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:-:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:beta1:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:beta2:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:rc1:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:a:redhat:ansible_automation_platform:2.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_developer:1.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_inside:1.2:*:*:*:*:*:*:*
OR cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 08:42

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X7Q6CHPVCHMZS5M7V22GOKFSXZAQ24EU/ -
  • () https://security.netapp.com/advisory/ntap-20241025-0001/ -
References () https://access.redhat.com/errata/RHSA-2023:7773 - Vendor Advisory () https://access.redhat.com/errata/RHSA-2023:7773 - Vendor Advisory
References () https://access.redhat.com/security/cve/CVE-2023-5764 - Vendor Advisory () https://access.redhat.com/security/cve/CVE-2023-5764 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2247629 - Issue Tracking, Patch, Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=2247629 - Issue Tracking, Patch, Vendor Advisory
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 7.1

16 Sep 2024, 17:16

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X7Q6CHPVCHMZS5M7V22GOKFSXZAQ24EU/', 'tags': ['Third Party Advisory'], 'source': 'secalert@redhat.com'}

25 Apr 2024, 16:15

Type Values Removed Values Added
Summary (en) A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce code injection when supplying templating data. (en) A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.

20 Dec 2023, 17:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE NVD-CWE-Other
CPE cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:-:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:beta1:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:rc1:*:*:*:*:*:*
cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_automation_platform:2.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_inside:1.2:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:beta2:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_developer:1.1:*:*:*:*:*:*:*
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X7Q6CHPVCHMZS5M7V22GOKFSXZAQ24EU/ - Third Party Advisory
References () https://access.redhat.com/security/cve/CVE-2023-5764 - () https://access.redhat.com/security/cve/CVE-2023-5764 - Vendor Advisory
References () https://access.redhat.com/errata/RHSA-2023:7773 - () https://access.redhat.com/errata/RHSA-2023:7773 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2247629 - () https://bugzilla.redhat.com/show_bug.cgi?id=2247629 - Issue Tracking, Patch, Vendor Advisory
First Time Redhat
Fedoraproject extra Packages For Enterprise Linux
Redhat enterprise Linux
Redhat ansible Automation Platform
Redhat ansible Developer
Redhat ansible Inside
Fedoraproject
Fedoraproject fedora
Redhat ansible

13 Dec 2023, 10:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2023:7773 -

12 Dec 2023, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-12 22:15

Updated : 2024-11-21 08:42


NVD link : CVE-2023-5764

Mitre link : CVE-2023-5764

CVE.ORG link : CVE-2023-5764


JSON object : View

Products Affected

redhat

  • ansible_automation_platform
  • ansible_developer
  • ansible_inside
  • enterprise_linux
  • ansible

fedoraproject

  • extra_packages_for_enterprise_linux
  • fedora
CWE
CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine

NVD-CWE-Other