A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.
History

Tue, 12 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 Nov 2024 01:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 11 Nov 2024 23:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.
Title Ansible-core: unsafe tagging bypass via hostvars object in ansible-core
First Time appeared Redhat
Redhat ansible Automation Platform
Redhat enterprise Linux Ai
Weaknesses CWE-20
CPEs cpe:/a:redhat:ansible_automation_platform:2
cpe:/a:redhat:enterprise_linux_ai:1
Vendors & Products Redhat
Redhat ansible Automation Platform
Redhat enterprise Linux Ai
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2024-11-11T23:32:55.539Z

Updated: 2024-11-12T14:42:14.546Z

Reserved: 2024-11-11T11:57:21.806Z

Link: CVE-2024-11079

cve-icon Vulnrichment

Updated: 2024-11-12T14:42:08.396Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-12T00:15:15.543

Modified: 2024-11-12T13:55:21.227

Link: CVE-2024-11079

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-11-11T00:00:00Z

Links: CVE-2024-11079 - Bugzilla