Oval Definition:oval:com.ubuntu.bionic:def:201774810000000
Revision Date:2018-07-19Version:1
Title:CVE-2017-7481 on Ubuntu 18.04 LTS (bionic) - low.
Description:Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not evaluated.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2017-7481
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND ansible package in bionic, is related to the CVE in some way and has been fixed (note: '2.5.1+dfsg-1').
  • BACK