Headline
Ubuntu Security Notice USN-6846-1
Ubuntu Security Notice 6846-1 - It was discovered that Ansible incorrectly handled certain inputs when using tower_callback parameter. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. It was discovered that Ansible incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to perform a Template Injection.
==========================================================================Ubuntu Security Notice USN-6846-1June 25, 2024ansible vulnerabilities==========================================================================A security issue affects these releases of Ubuntu and its derivatives:- Ubuntu 22.04 LTS- Ubuntu 20.04 LTS- Ubuntu 18.04 LTS- Ubuntu 16.04 LTSSummary:Several security issues were fixed in Ansible.Software Description:- ansible: Configuration management, deployment, and task execution systemDetails:It was discovered that Ansible incorrectly handled certain inputs when usingtower_callback parameter. If a user or an automated system were tricked intoopening a specially crafted input file, a remote attacker could possibly usethis issue to obtain sensitive information. This issue only affected Ubuntu18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2022-3697)It was discovered that Ansible incorrectly handled certain inputs. If a user oran automated system were tricked into opening a specially crafted input file, aremote attacker could possibly use this issue to perform a Template Injection.(CVE-2023-5764)Update instructions:The problem can be corrected by updating your system to the followingpackage versions:Ubuntu 22.04 LTS ansible 2.10.7+merged+base+2.10.8+dfsg-1ubuntu0.1~esm4 Available with Ubuntu ProUbuntu 20.04 LTS ansible 2.9.6+dfsg-1ubuntu0.1~esm2 Available with Ubuntu ProUbuntu 18.04 LTS ansible 2.5.1+dfsg-1ubuntu0.1+esm2 Available with Ubuntu ProUbuntu 16.04 LTS ansible 2.0.0.2-2ubuntu1.3+esm2 Available with Ubuntu ProIn general, a standard system update will make all the necessary changes.References: https://ubuntu.com/security/notices/USN-6846-1 CVE-2022-3697, CVE-2023-5764
Related news
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce code injection when supplying templating data.
A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.