CVE-2017-7481: Canonical Ubuntu Linux
Critical severity, CVSS 9.8. EPSS: 4.8% chance of exploitation in the next 30 days.
Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not evaluated.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only
- Debian Debian Linux: version 9.0 only
- Red Hat Ansible Engine: before 2.3.1.0 (fixed in 2.3.1.0); from 2.3.2.0, before 2.4.0.0 (fixed in 2.4.0.0)
- Red Hat Gluster Storage: version 3.2 only
- Red Hat Openshift Container Platform: version 3.3 only; version 3.4 only; version 3.5 only
- Red Hat Openstack: version 10 only; version 11 only
- Red Hat Storage Console: version 2.0 only
- Red Hat Virtualization: version 4.1 only
- Red Hat Virtualization Manager: version 4.1 only
Published 2018-07-19. Last modified 2026-06-17.