QID 996475
Date Published: 2024-01-04
QID 996475: Python (Pip) Security Update for ansible-core (GHSA-7j69-qfc3-2fq9)
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce code injection when supplying templating data.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-7j69-qfc3-2fq9 for updates and patch information.
Vendor References
- GHSA-7j69-qfc3-2fq9 -
github.com/advisories/GHSA-7j69-qfc3-2fq9
CVEs related to QID 996475
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7j69-qfc3-2fq9 | ansible-core |
|