CVE Database
/

CVE-2017-7481

Back to search

CVE-2017-7481

Published: Jul 19, 2018

Modified: Aug 5, 2024

PUBLISHED

CVSS v3.0

5.3

MEDIUM

Description

Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not evaluated.

VendorProductVersions

[UNKNOWN]

ansible

affected
ansible 2.3.1.0
affected
ansible 2.4.0.0

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

None

Integrity

High

Availability

None

References

RHSA-2017:1599
vendor-advisory
x_refsource_REDHAT
RHSA-2017:1334
vendor-advisory
x_refsource_REDHAT
98492
vdb-entry
x_refsource_BID
RHSA-2017:1244
vendor-advisory
x_refsource_REDHAT
RHSA-2017:1499
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2524
vendor-advisory
x_refsource_REDHAT
RHSA-2017:1476
vendor-advisory
x_refsource_REDHAT
USN-4072-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now