CVE-2024-11079

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.
Configurations

No configuration.

History

18 Dec 2024, 04:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:11145 -

04 Dec 2024, 02:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:10770 -

12 Nov 2024, 13:55

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en Ansible-Core. Esta vulnerabilidad permite a los atacantes eludir las protecciones de contenido inseguro mediante el objeto hostvars para hacer referencia y ejecutar contenido con plantilla. Este problema puede provocar la ejecución de código arbitrario si los datos remotos o las salidas de módulos tienen plantillas incorrectas dentro de los playbooks.

12 Nov 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-12 00:15

Updated : 2024-12-18 04:15


NVD link : CVE-2024-11079

Mitre link : CVE-2024-11079

CVE.ORG link : CVE-2024-11079


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation