CVE-2023-5764: Ansible: template injection
A flaw was found in Ansible, where a user's controller is vulnerable to template injection when internal templating operations may errantly remove the unsafe designation from template data.
Other sources
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5764?
The severity of CVE-2023-5764 is categorized as medium due to the potential for template injection.
How do I fix CVE-2023-5764?
To fix CVE-2023-5764, upgrade to Ansible version 2.10.8 or later, or an appropriate patched version as listed in the remediation guide.
Which versions are affected by CVE-2023-5764?
CVE-2023-5764 affects several versions of Ansible, specifically those prior to 2.10.8 and certain versions of Ansible-Core.
What is template injection in the context of CVE-2023-5764?
Template injection in CVE-2023-5764 refers to a flaw whereby unsafe template data could be executed, leading to potential unauthorized actions.
Are all distributions of Ansible affected by CVE-2023-5764?
No, not all distributions of Ansible are affected; the vulnerability primarily impacts specific versions from Debian, Red Hat, and Fedora.