320
VMScore

CVE-2021-3583

Published: 22/09/2021 Updated: 28/12/2023
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows malicious users to perform command injection, which discloses sensitive information. The highest threat from this vulnerability is to confidentiality and integrity.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat ansible automation platform 1.2

redhat ansible tower

redhat ansible engine

Vendor Advisories

A flaw was found in Ansible, where a user's controller is vulnerable to template injection This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters This flaw allows attackers to perform command injectio ...
No description is available for this CVE ...
A security issue was found in Ansible, where a user's controller is vulnerable to template injection This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters This flaw allows attackers to perform comman ...