CVE-2021-3583 log
Source |
|
Severity | Medium |
Remote | Yes |
Type | Arbitrary command execution |
Description | A security issue was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows attackers to perform command injection, which discloses sensitive information. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-2260 | ansible-core | 2.11.2-1 | 2.11.3-1 | Medium | Fixed |
References |
---|
https://bugzilla.redhat.com/show_bug.cgi?id=1968412 https://github.com/ansible/ansible/pull/74960 https://github.com/ansible/ansible/commit/4c8c40fd3d4a58defdc80e7d22aa8d26b731353e |