← Back

CVE-2017-7481

nvd nist
Published: Jul 19, 2018Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not evaluated.

Affected (15)

7 products
Openshift Container Platform
Openstack
Storage Console
Virtualization
Virtualization Manager
Gluster Storage
Ansible Engine
1 product
Ubuntu Linux
1 product
Debian Linux
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 3.3
Version 3.4
Version 3.5
Redhat
Version 10
Version 11
Version 2.0
Version 4.1
Version 4.1
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 3.2
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 7.0
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Before 2.3.1.0
From 2.3.2.0 to 2.4.0.0
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 16.04
Version 18.04
Version 19.04
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0

References (22)

Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Issue TrackingPatchVendor Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.