Loading HuntDB...

GHSA-7j69-qfc3-2fq9

GitHub Security Advisory

Ansible template injection vulnerability

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.

Affected Packages

PyPI ansible-core
Affected versions: 2.16.0 (fixed in 2.16.1)
PyPI ansible-core
Affected versions: 2.15.0 (fixed in 2.15.8)
PyPI ansible-core
Affected versions: 0 (fixed in 2.14.12)

Related CVEs

Key Information

GHSA ID
GHSA-7j69-qfc3-2fq9
Published
December 13, 2023 12:30 AM
Last Modified
September 16, 2024 9:08 PM
CVSS Score
5.0 /10
Primary Ecosystem
PyPI
Primary Package
ansible-core
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.