CVE-2023-5764

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:-:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:beta1:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:beta2:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:rc1:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:a:redhat:ansible_automation_platform:2.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_developer:1.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_inside:1.2:*:*:*:*:*:*:*
OR cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 08:42

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X7Q6CHPVCHMZS5M7V22GOKFSXZAQ24EU/ -
  • () https://security.netapp.com/advisory/ntap-20241025-0001/ -
References () https://access.redhat.com/errata/RHSA-2023:7773 - Vendor Advisory () https://access.redhat.com/errata/RHSA-2023:7773 - Vendor Advisory
References () https://access.redhat.com/security/cve/CVE-2023-5764 - Vendor Advisory () https://access.redhat.com/security/cve/CVE-2023-5764 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2247629 - Issue Tracking, Patch, Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=2247629 - Issue Tracking, Patch, Vendor Advisory
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 7.1

16 Sep 2024, 17:16

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X7Q6CHPVCHMZS5M7V22GOKFSXZAQ24EU/', 'tags': ['Third Party Advisory'], 'source': 'secalert@redhat.com'}

25 Apr 2024, 16:15

Type Values Removed Values Added
Summary (en) A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce code injection when supplying templating data. (en) A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.

20 Dec 2023, 17:35

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2023:7773 - () https://access.redhat.com/errata/RHSA-2023:7773 - Vendor Advisory
References () https://access.redhat.com/security/cve/CVE-2023-5764 - () https://access.redhat.com/security/cve/CVE-2023-5764 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2247629 - () https://bugzilla.redhat.com/show_bug.cgi?id=2247629 - Issue Tracking, Patch, Vendor Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X7Q6CHPVCHMZS5M7V22GOKFSXZAQ24EU/ - () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X7Q6CHPVCHMZS5M7V22GOKFSXZAQ24EU/ - Third Party Advisory
First Time Redhat ansible
Redhat
Redhat ansible Inside
Fedoraproject extra Packages For Enterprise Linux
Fedoraproject fedora
Redhat ansible Automation Platform
Redhat enterprise Linux
Fedoraproject
Redhat ansible Developer
CVSS v2 : unknown
v3 : 6.6
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:redhat:ansible:2.16.0:-:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:beta1:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_inside:1.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:rc1:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:beta2:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_developer:1.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_automation_platform:2.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
CWE NVD-CWE-Other

20 Dec 2023, 02:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X7Q6CHPVCHMZS5M7V22GOKFSXZAQ24EU/ -

12 Dec 2023, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-12 22:15

Updated : 2024-11-21 08:42


NVD link : CVE-2023-5764

Mitre link : CVE-2023-5764

CVE.ORG link : CVE-2023-5764


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • ansible_inside
  • ansible_developer
  • ansible_automation_platform
  • ansible

fedoraproject

  • extra_packages_for_enterprise_linux
  • fedora
CWE
CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine

NVD-CWE-Other