CVE-2017-7481 -- ansibleID: oval:org.secpod.oval:def:1900358 | Date: (C)2019-02-28 (M)2023-12-20 |
Class: VULNERABILITY | Family: unix |
Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly marklookup-plugin results as unsafe. If an attacker could control the results of lookup calls, they could inject Unicode strings to be parsed by the jinja2 templating system, result ing in code execution. By default, the jinja2 templating language is now marked as "unsafe" and is not evaluated.
Platform: |
Ubuntu 16.04 |
Ubuntu 14.04 |