CVE-2023-5764
published 2023-12-12CVE-2023-5764: A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.54%
41.8th percentile
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 5.4.0-1 (bookworm) | ansible 5.4.0-1 (bookworm) |
| debian | ansible-core | < ansible 5.4.0-1 (bookworm) | ansible 5.4.0-1 (bookworm) |
| fedoraproject | extra_packages_for_enterprise_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_ansible_2.15.3-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_ansible_2.17.0-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_ansible_2.14.12-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| redhat | ansible | < 2.14.12 | 2.14.12 |
| redhat | ansible | — | — |
| redhat | ansible | >= 0 < 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1 | 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1 |
| redhat | ansible | >= 0 < 5.4.0-1 | 5.4.0-1 |
| redhat | ansible | >= 0 < 5.4.0-1 | 5.4.0-1 |
| redhat | ansible | >= 0 < 5.4.0-1 | 5.4.0-1 |
| redhat | ansible | >= 0 < 2.0.0.2-2ubuntu1.3+esm2 | 2.0.0.2-2ubuntu1.3+esm2 |
| redhat | ansible | >= 0 < 2.0.0.2-2ubuntu1.3+esm3 | 2.0.0.2-2ubuntu1.3+esm3 |
| redhat | ansible | >= 0 < 2.5.1+dfsg-1ubuntu0.1+esm2 | 2.5.1+dfsg-1ubuntu0.1+esm2 |
| redhat | ansible | >= 0 < 2.5.1+dfsg-1ubuntu0.1+esm3 | 2.5.1+dfsg-1ubuntu0.1+esm3 |
| redhat | ansible | >= 0 < 2.9.6+dfsg-1ubuntu0.1~esm2 | 2.9.6+dfsg-1ubuntu0.1~esm2 |
| redhat | ansible | >= 0 < 2.10.7+merged+base+2.10.8+dfsg-1ubuntu0.1~esm4 | 2.10.7+merged+base+2.10.8+dfsg-1ubuntu0.1~esm4 |
| redhat | ansible | >= 2.15.0 < 2.15.7 | 2.15.7 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_msrc7.8HIGH
vendor_oracle7.8HIGH
vendor_ubuntu7.5HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ansible regression
vendor_ubuntu·2025-02-13·CVSS 7.5
[HIGH] Ansible regression
Title: Ansible regression
Summary: USN-6846-2 caused some regression in ansible.
USN-6846-1 fixed vulnerabilities in ansible. The update introduced a
regression in ansible. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Ansible incorrectly handled certain inputs when
using tower_callback parameter. If a user or an automated system were
tricked into opening a specially crafted input file, a remote attacker
could possibly use this issue to obtain sensitive information. This issue
only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2022-3697)
It was discovered that Ansible incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input f
Ubuntu
Ansible regression
vendor_ubuntu·2024-12-02·CVSS 7.5
[HIGH] Ansible regression
Title: Ansible regression
Summary: USN-6846-1 caused some regression in ansible.
USN-6846-1 fixed vulnerabilities in ansible. The update introduced a
regression in ansible. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Ansible incorrectly handled certain inputs when
using tower_callback parameter. If a user or an automated system were
tricked into opening a specially crafted input file, a remote attacker
could possibly use this issue to obtain sensitive information. This issue
only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2022-3697)
It was discovered that Ansible incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input f
Oracle
Oracle Oracle Siebel CRM Risk Matrix: Siebel Cloud Manager (Ansible) — CVE-2023-5764
vendor_oracle·2024-07-15·CVSS 7.8
CVE-2023-5764 [HIGH] Oracle Oracle Siebel CRM Risk Matrix: Siebel Cloud Manager (Ansible) — CVE-2023-5764
Oracle Oracle Siebel CRM Risk Matrix: Siebel Cloud Manager (Ansible) vulnerability
CVE: CVE-2023-5764
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2024 (JUL 2024)
Ubuntu
Ansible vulnerabilities
vendor_ubuntu·2024-06-25·CVSS 7.5
CVE-2023-5764 [HIGH] Ansible vulnerabilities
Title: Ansible vulnerabilities
Summary: Several security issues were fixed in Ansible.
It was discovered that Ansible incorrectly handled certain inputs when using
tower_callback parameter. If a user or an automated system were tricked into
opening a specially crafted input file, a remote attacker could possibly use
this issue to obtain sensitive information. This issue only affected Ubuntu
18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2022-3697)
It was discovered that Ansible incorrectly handled certain inputs. If a user or
an automated system were tricked into opening a specially crafted input file, a
remote attacker could possibly use this issue to perform a Template Injection.
(CVE-2023-5764)
Instructions: In general, a standard system update will make all the necessary c
Microsoft
Ansible: template injection
vendor_msrc·2023-12-12·CVSS 7.8
CVE-2023-5764 [HIGH] CWE-1336 Ansible: template injection
Ansible: template injection
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure
Red Hat
ansible: Template Injection
vendor_redhat·2023-11-02·CVSS 7.1
CVE-2023-5764 [HIGH] CWE-1336 ansible: Template Injection
ansible: Template Injection
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
Debian
CVE-2023-5764: ansible - A template injection flaw was found in Ansible where a user's controller interna...
vendor_debian·2023·CVSS 7.1
CVE-2023-5764 [HIGH] CVE-2023-5764: ansible - A template injection flaw was found in Ansible where a user's controller interna...
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
Scope: local
bookworm: resolved (fixed in 5.4.0-1)
bullseye: resolved (fixed in 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1)
forky: resolved (fixed in 5.4.0-1)
sid: resolved (fixed in 5.4.0-1)
trixie: resolved (fixed in 5.4.0-1)
OSV
ansible regression
osv·2024-12-02·CVSS 7.5
[HIGH] ansible regression
ansible regression
USN-6846-1 fixed vulnerabilities in ansible. The update introduced a
regression in ansible. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Ansible incorrectly handled certain inputs when
using tower_callback parameter. If a user or an automated system were
tricked into opening a specially crafted input file, a remote attacker
could possibly use this issue to obtain sensitive information. This issue
only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2022-3697)
It was discovered that Ansible incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to perform
OSV
ansible vulnerabilities
osv·2024-06-25·CVSS 7.5
CVE-2022-3697 [HIGH] ansible vulnerabilities
ansible vulnerabilities
It was discovered that Ansible incorrectly handled certain inputs when using
tower_callback parameter. If a user or an automated system were tricked into
opening a specially crafted input file, a remote attacker could possibly use
this issue to obtain sensitive information. This issue only affected Ubuntu
18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2022-3697)
It was discovered that Ansible incorrectly handled certain inputs. If a user or
an automated system were tricked into opening a specially crafted input file, a
remote attacker could possibly use this issue to perform a Template Injection.
(CVE-2023-5764)
OSV
Ansible template injection vulnerability
osv·2023-12-13
CVE-2023-5764 [MEDIUM] Ansible template injection vulnerability
Ansible template injection vulnerability
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
GHSA
Ansible template injection vulnerability
ghsa·2023-12-13
CVE-2023-5764 [MEDIUM] CWE-1336 Ansible template injection vulnerability
Ansible template injection vulnerability
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
OSV
CVE-2023-5764: A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from templat
osv·2023-12-12·CVSS 7.8
CVE-2023-5764 [HIGH] CVE-2023-5764: A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from templat
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-5764 ansible: Template Injection
bugzilla·2023-11-02·CVSS 7.8
CVE-2023-5764 [HIGH] CVE-2023-5764 ansible: Template Injection
CVE-2023-5764 ansible: Template Injection
A flaw was found in Ansible, where a user's controller is vulnerable to template injection when internal templating operations may errantly remove the unsafe designation from template data.
Discussion:
Created ansible tracking bugs for this issue:
Affects: epel-all [bug 2247631]
Affects: fedora-all [bug 2247630]
---
Is this an issue which has an upstream fix in the Ansible project? Are there details on the issue to determine downstream affected versions?
---
yes,look here
https://github.com/ansible/ansible/pull/82293
https://github.com/ansible/ansible/pull/82294
https://github.com/ansible/ansible/pull/82295
---
(In reply to Vipul Nair from comment #4)
> yes,look here
> https://github.com/ansible/ansible/pull/82293
> https://github.com/ans
Bugzilla
CVE-2023-5764 ansible: Template Injection [epel-all]
bugzilla·2023-11-02·CVSS 7.8
CVE-2023-5764 [HIGH] CVE-2023-5764 ansible: Template Injection [epel-all]
CVE-2023-5764 ansible: Template Injection [epel-all]
More information about this security flaw is available in the following bug:
http://bugzilla.redhat.com/show_bug.cgi?id=2247629
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# low, medium, high, urgent (required)
sev
https://access.redhat.com/errata/RHSA-2023:7773https://access.redhat.com/security/cve/CVE-2023-5764https://bugzilla.redhat.com/show_bug.cgi?id=2247629https://access.redhat.com/errata/RHSA-2023:7773https://access.redhat.com/security/cve/CVE-2023-5764https://bugzilla.redhat.com/show_bug.cgi?id=2247629https://lists.fedoraproject.org/archives/list/[email protected]/message/X7Q6CHPVCHMZS5M7V22GOKFSXZAQ24EU/https://security.netapp.com/advisory/ntap-20241025-0001/
2023-12-12
Published