CVE-2023-5764Medium· 6.6▾ SunlitAnsible template injection vulnerability
▾ Sunlit zone — Low / medium · no exploitation signal
impact 36.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
0.5% → 0.5%
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
ansible-core >= 2.16.0, < 2.16.1ansible-core >= 2.15.0, < 2.15.8ansible-core < 2.14.12Upgrade to a patched release:
ansible-core 2.16.1ansible-core 2.15.8ansible-core 2.14.12Connected by shared product, vendor, weakness, or advisory.
CVE-2023-4237Medium· 6.5Ansible may expose private key
CVE-2024-8775Medium· 5.5A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook
CVE-2024-9902Medium· 6.3ansible-core Incorrect Authorization vulnerability
CVE-2024-11079Medium· 5.5A flaw was found in Ansible-Core
CVE-2026-11332High· 7.8A flaw was found in ansible-core