Security
Headlines
HeadlinesLatestCVEs

Headline

Ubuntu Security Notice USN-6846-1

Ubuntu Security Notice 6846-1 - It was discovered that Ansible incorrectly handled certain inputs when using tower_callback parameter. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. It was discovered that Ansible incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to perform a Template Injection.

Packet Storm
#vulnerability#ubuntu
==========================================================================Ubuntu Security Notice USN-6846-1June 25, 2024ansible vulnerabilities==========================================================================A security issue affects these releases of Ubuntu and its derivatives:- Ubuntu 22.04 LTS- Ubuntu 20.04 LTS- Ubuntu 18.04 LTS- Ubuntu 16.04 LTSSummary:Several security issues were fixed in Ansible.Software Description:- ansible: Configuration management, deployment, and task execution systemDetails:It was discovered that Ansible incorrectly handled certain inputs when usingtower_callback parameter. If a user or an automated system were tricked intoopening a specially crafted input file, a remote attacker could possibly usethis issue to obtain sensitive information. This issue only affected Ubuntu18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2022-3697)It was discovered that Ansible incorrectly handled certain inputs. If a user oran automated system were tricked into opening a specially crafted input file, aremote attacker could possibly use this issue to perform a Template Injection.(CVE-2023-5764)Update instructions:The problem can be corrected by updating your system to the followingpackage versions:Ubuntu 22.04 LTS   ansible                         2.10.7+merged+base+2.10.8+dfsg-1ubuntu0.1~esm4                                   Available with Ubuntu ProUbuntu 20.04 LTS   ansible                         2.9.6+dfsg-1ubuntu0.1~esm2                                   Available with Ubuntu ProUbuntu 18.04 LTS   ansible                         2.5.1+dfsg-1ubuntu0.1+esm2                                   Available with Ubuntu ProUbuntu 16.04 LTS   ansible                         2.0.0.2-2ubuntu1.3+esm2                                   Available with Ubuntu ProIn general, a standard system update will make all the necessary changes.References:   https://ubuntu.com/security/notices/USN-6846-1   CVE-2022-3697, CVE-2023-5764

Related news

CVE-2023-5764: cve-details

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce code injection when supplying templating data.

CVE-2022-3697: ec2_instance - validate options on tower_callback by tremble · Pull Request #1199 · ansible-collections/amazon.aws

A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.

Packet Storm: Latest News

Zeek 6.0.8