A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
| Software | From | Fixed in |
|---|---|---|
| redhat / ansible | 2.16.0-beta1 | 2.16.0-beta1.x |
| redhat / ansible | 2.16.0-beta2 | 2.16.0-beta2.x |
| redhat / ansible | 2.16.0-rc1 | 2.16.0-rc1.x |
| redhat / ansible | 2.15.0 | 2.15.7 |
| redhat / ansible | - | 2.14.12 |
| redhat / ansible | 2.16.0 | 2.16.0.x |
| fedoraproject / extra_packages_for_enterprise_linux | 8.0 | 8.0.x |
| fedoraproject / fedora | 38 | 38.x |
| fedoraproject / fedora | 39 | 39.x |
| redhat / ansible_automation_platform | 2.4 | 2.4.x |
| redhat / ansible_developer | 1.1 | 1.1.x |
| redhat / ansible_inside | 1.2 | 1.2.x |
ansible-core
|
2.16.0 | 2.16.1 |
ansible-core
|
2.15.0 | 2.15.8 |
ansible-core
|
- | 2.14.12 |