CVE-2023-5764: Fedoraproject Extra Packages For Enterprise Linux

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.

Affected products

  • Fedoraproject Extra Packages For Enterprise Linux: version 8.0 only
  • Fedoraproject Fedora: version 38 only; version 39 only
  • Red Hat Ansible: before 2.14.12 (fixed in 2.14.12); from 2.15.0, before 2.15.7 (fixed in 2.15.7); version 2.16.0 only
  • Red Hat Ansible Automation Platform: version 2.4 only
  • Red Hat Ansible Developer: version 1.1 only
  • Red Hat Ansible Inside: version 1.2 only

Published 2023-12-12. Last modified 2026-06-17.