Upstream information

CVE-2014-4966 at MITRE

Description

Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which allows remote attackers to execute arbitrary code via (1) crafted lookup('pipe') calls or (2) crafted Jinja2 data.

SUSE information

Overall state of this security issue: Does not affect SUSE products

No SUSE Bugzilla entries cross referenced.

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
openSUSE Tumbleweed
  • ansible >= 2.2.0.0-1.1
  • ansible-10 >= 10.6.0-1.1
  • ansible-9 >= 9.8.0-1.1
Patchnames:
openSUSE-Tumbleweed-2024-10326
openSUSE-Tumbleweed-2024-14244
openSUSE-Tumbleweed-2024-14536


SUSE Timeline for this CVE

CVE page created: Tue Jul 22 16:34:23 2014
CVE page last modified: Tue Dec 3 00:17:47 2024