ISOMAN

CVE

CVE-2017-7481

Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not evaluated.

Severity
CRITICAL
CVSS
9.8
Published
Modified

Linked Releases

References

  1. http://www.securityfocus.com/bid/98492
  2. https://access.redhat.com/errata/RHSA-2017:1244
  3. https://access.redhat.com/errata/RHSA-2017:1334
  4. https://access.redhat.com/errata/RHSA-2017:1476
  5. https://access.redhat.com/errata/RHSA-2017:1499
  6. https://access.redhat.com/errata/RHSA-2017:1599
  7. https://access.redhat.com/errata/RHSA-2017:2524
  8. https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7481
  9. https://github.com/ansible/ansible/commit/ed56f51f185a1ffd7ea57130d260098686fcc7c2
  10. https://lists.debian.org/debian-lts-announce/2021/01/msg00023.html
  11. https://usn.ubuntu.com/4072-1/
  12. http://www.securityfocus.com/bid/98492
  13. https://access.redhat.com/errata/RHSA-2017:1244
  14. https://access.redhat.com/errata/RHSA-2017:1334
  15. https://access.redhat.com/errata/RHSA-2017:1476
  16. https://access.redhat.com/errata/RHSA-2017:1499
  17. https://access.redhat.com/errata/RHSA-2017:1599
  18. https://access.redhat.com/errata/RHSA-2017:2524
  19. https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7481
  20. https://github.com/ansible/ansible/commit/ed56f51f185a1ffd7ea57130d260098686fcc7c2