CVE-2023-5764: Fedoraproject Extra Packages For Enterprise Linux
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
Affected products
- Fedoraproject Extra Packages For Enterprise Linux: version 8.0 only
- Fedoraproject Fedora: version 38 only; version 39 only
- Red Hat Ansible: before 2.14.12 (fixed in 2.14.12); from 2.15.0, before 2.15.7 (fixed in 2.15.7); version 2.16.0 only
- Red Hat Ansible Automation Platform: version 2.4 only
- Red Hat Ansible Developer: version 1.1 only
- Red Hat Ansible Inside: version 1.2 only
Published 2023-12-12. Last modified 2026-06-17.