A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.
History

Wed, 18 Dec 2024 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat ansible Automation Platform Developer
Redhat ansible Automation Platform Inside
CPEs cpe:/a:redhat:ansible_automation_platform:2 cpe:/a:redhat:ansible_automation_platform_developer:2.5::el8
cpe:/a:redhat:ansible_automation_platform_developer:2.5::el9
cpe:/a:redhat:ansible_automation_platform_inside:2.5::el8
cpe:/a:redhat:ansible_automation_platform_inside:2.5::el9
Vendors & Products Redhat ansible Automation Platform Developer
Redhat ansible Automation Platform Inside
References

Tue, 17 Dec 2024 02:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:ansible_automation_platform:2.5::el8
cpe:/a:redhat:ansible_automation_platform:2.5::el9

Wed, 04 Dec 2024 01:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:ansible_automation_platform:ee::el8
cpe:/a:redhat:ansible_automation_platform:ee::el9
References

Tue, 12 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 Nov 2024 01:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 11 Nov 2024 23:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.
Title Ansible-core: unsafe tagging bypass via hostvars object in ansible-core
First Time appeared Redhat
Redhat ansible Automation Platform
Redhat enterprise Linux Ai
Weaknesses CWE-20
CPEs cpe:/a:redhat:ansible_automation_platform:2
cpe:/a:redhat:enterprise_linux_ai:1
Vendors & Products Redhat
Redhat ansible Automation Platform
Redhat enterprise Linux Ai
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2024-11-11T23:32:55.539Z

Updated: 2024-12-18T03:58:07.309Z

Reserved: 2024-11-11T11:57:21.806Z

Link: CVE-2024-11079

cve-icon Vulnrichment

Updated: 2024-11-12T14:42:08.396Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-12T00:15:15.543

Modified: 2024-12-18T04:15:06.310

Link: CVE-2024-11079

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-11-11T00:00:00Z

Links: CVE-2024-11079 - Bugzilla