QID 997079
Date Published: 2024-02-02
QID 997079: Python (Pip) Security Update for ansible (GHSA-wqq5-c89p-3wc3)
Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which allows remote attackers to execute arbitrary code via (1) crafted lookup('pipe') calls or (2) crafted Jinja2 data.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-wqq5-c89p-3wc3 for updates and patch information.
Vendor References
- GHSA-wqq5-c89p-3wc3 -
github.com/advisories/GHSA-wqq5-c89p-3wc3
CVEs related to QID 997079
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wqq5-c89p-3wc3 | ansible |
|