CVE-2017-7481
Summary
| CVE | CVE-2017-7481 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-19 13:29:00 UTC |
| Updated | 2021-08-04 17:15:00 UTC |
| Description | Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not evaluated. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Vendor Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Vendor Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Vendor Advisory |
| [SECURITY] [DLA 2535-1] ansible security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| USN-4072-1: Ansible vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| 1450018 – (CVE-2017-7481) CVE-2017-7481 ansible: Security issue with lookup return not tainting the jinja2 environment |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Patch, Vendor Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Vendor Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Vendor Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Vendor Advisory |
| Ansible CVE-2017-7481 Security Bypass Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Fixing security issue with lookup returns not tainting the jinja2 env… · ansible/ansible@ed56f51 · GitHub |
CONFIRM |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980827 Python (pip) Security Update for ansible (GHSA-w578-j992-554x)