Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2017-7481
Description:Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not evaluated.
Test IDs: 1.3.6.1.4.1.25623.1.0.892535   1.3.6.1.4.1.25623.1.0.872754   1.3.6.1.4.1.25623.1.0.872750  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2017-7481
BugTraq ID: 98492
http://www.securityfocus.com/bid/98492
https://lists.debian.org/debian-lts-announce/2021/01/msg00023.html
RedHat Security Advisories: RHSA-2017:1244
https://access.redhat.com/errata/RHSA-2017:1244
RedHat Security Advisories: RHSA-2017:1334
https://access.redhat.com/errata/RHSA-2017:1334
RedHat Security Advisories: RHSA-2017:1476
https://access.redhat.com/errata/RHSA-2017:1476
RedHat Security Advisories: RHSA-2017:1499
https://access.redhat.com/errata/RHSA-2017:1499
RedHat Security Advisories: RHSA-2017:1599
https://access.redhat.com/errata/RHSA-2017:1599
RedHat Security Advisories: RHSA-2017:2524
https://access.redhat.com/errata/RHSA-2017:2524
https://usn.ubuntu.com/4072-1/




© 1998-2025 E-Soft Inc. All rights reserved.