CVE-2024-11079
published 2024-11-12CVE-2024-11079: A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute…
PriorityP432medium5.5CVSS 3.1
AVNACHPRLUIRSCCLILAL
EPSS
0.50%
39.6th percentile
A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 5.4.0-1 (bookworm) | ansible 5.4.0-1 (bookworm) |
| debian | ansible-core | < ansible 5.4.0-1 (bookworm) | ansible 5.4.0-1 (bookworm) |
| redhat | ansible | >= 0 < 2.10.7+merged+base+2.10.17+dfsg-0+deb11u4 | 2.10.7+merged+base+2.10.17+dfsg-0+deb11u4 |
| redhat | ansible | >= 0 < 5.4.0-1 | 5.4.0-1 |
| redhat | ansible | >= 0 < 5.4.0-1 | 5.4.0-1 |
| redhat | ansible | >= 0 < 5.4.0-1 | 5.4.0-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ansible-core: Unsafe Tagging Bypass via hostvars Object in Ansible-Core
vendor_redhat·2024-11-11·CVSS 5.5
CVE-2024-11079 [MEDIUM] CWE-20 ansible-core: Unsafe Tagging Bypass via hostvars Object in Ansible-Core
ansible-core: Unsafe Tagging Bypass via hostvars Object in Ansible-Core
A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.
A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.
Mitigation: To mitigate this vulnerability, avoid using the hostvars object to reference content marked as !unsafe. Ensure
Debian
CVE-2024-11079: ansible - A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass ...
vendor_debian·2024·CVSS 5.5
CVE-2024-11079 [MEDIUM] CVE-2024-11079: ansible - A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass ...
A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.
Scope: local
bookworm: resolved (fixed in 5.4.0-1)
bullseye: resolved (fixed in 2.10.7+merged+base+2.10.17+dfsg-0+deb11u4)
forky: resolved (fixed in 5.4.0-1)
sid: resolved (fixed in 5.4.0-1)
trixie: resolved (fixed in 5.4.0-1)
GHSA
Ansible-Core vulnerable to content protections bypass
ghsa·2024-11-12
CVE-2024-11079 [LOW] CWE-20 Ansible-Core vulnerable to content protections bypass
Ansible-Core vulnerable to content protections bypass
A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.
OSV
CVE-2024-11079: A flaw was found in Ansible-Core
osv·2024-11-12·CVSS 5.5
CVE-2024-11079 [MEDIUM] CVE-2024-11079: A flaw was found in Ansible-Core
A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.
OSV
Ansible-Core vulnerable to content protections bypass
osv·2024-11-12
CVE-2024-11079 [LOW] Ansible-Core vulnerable to content protections bypass
Ansible-Core vulnerable to content protections bypass
A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.
No detection rules found.
No public exploits indexed.
2024-11-12
Published