CVE-2024-11079Medium· 5.5▾ SunlitA flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote da…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
ansible-core >= 2.18.0b1, < 2.18.1rc1ansible-core >= 2.17.0b1, < 2.17.7rc1ansible-core < 2.16.14rc1Patched in:
ansible-core 2.18.1rc1ansible-core 2.17.7rc1ansible-core 2.16.14rc1Connected by shared product, vendor, weakness, or advisory.
CVE-2023-4237Medium· 6.5Ansible may expose private key
CVE-2024-8775Medium· 5.5A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook
CVE-2023-5764Medium· 6.6Ansible template injection vulnerability
CVE-2024-9902Medium· 6.3ansible-core Incorrect Authorization vulnerability
CVE-2026-11332High· 7.8A flaw was found in ansible-core
CVE-2021-45105Medium· 5.9Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups