CVE-2021-3583 log
| Source |
|
| Severity | Medium |
| Remote | Yes |
| Type | Arbitrary command execution |
| Description | A security issue was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows attackers to perform command injection, which discloses sensitive information. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-2260 | ansible-core | 2.11.2-1 | 2.11.3-1 | Medium | Fixed |
| References |
|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1968412 https://github.com/ansible/ansible/pull/74960 https://github.com/ansible/ansible/commit/4c8c40fd3d4a58defdc80e7d22aa8d26b731353e |