A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.
Metrics
Affected Vendors & Products
References
History
Tue, 12 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 12 Nov 2024 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Mon, 11 Nov 2024 23:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks. | |
Title | Ansible-core: unsafe tagging bypass via hostvars object in ansible-core | |
First Time appeared |
Redhat
Redhat ansible Automation Platform Redhat enterprise Linux Ai |
|
Weaknesses | CWE-20 | |
CPEs | cpe:/a:redhat:ansible_automation_platform:2 cpe:/a:redhat:enterprise_linux_ai:1 |
|
Vendors & Products |
Redhat
Redhat ansible Automation Platform Redhat enterprise Linux Ai |
|
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2024-11-11T23:32:55.539Z
Updated: 2024-11-12T14:42:14.546Z
Reserved: 2024-11-11T11:57:21.806Z
Link: CVE-2024-11079
Vulnrichment
Updated: 2024-11-12T14:42:08.396Z
NVD
Status : Awaiting Analysis
Published: 2024-11-12T00:15:15.543
Modified: 2024-11-12T13:55:21.227
Link: CVE-2024-11079
Redhat