Vulnerability Name: | CVE-2021-3583 (CCN-209925) | ||||||||||||||||||||||||||||||||
Assigned: | 2021-09-21 | ||||||||||||||||||||||||||||||||
Published: | 2021-09-21 | ||||||||||||||||||||||||||||||||
Updated: | 2022-10-07 | ||||||||||||||||||||||||||||||||
Summary: | A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows attackers to perform command injection, which discloses sensitive information. The highest threat from this vulnerability is to confidentiality and integrity. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.1 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) 6.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 3.6 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-94 | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-3583 Source: CCN Type: Red Hat Bugzilla - Bug 1968412 (CVE-2021-3583) - CVE-2021-3583 ansible: Template Injection through yaml multi-line strings with ansible facts used in template Source: MISC Type: Issue Tracking, Vendor Advisory https://bugzilla.redhat.com/show_bug.cgi?id=1968412 Source: XF Type: UNKNOWN ansible-cve20213583-command-exec(209925) Source: CCN Type: Ansible Web site Ansible is Simple IT Automation Source: CCN Type: IBM Security Bulletin 6560038 (Elastic Storage System) Ansible vulnerability affects IBM Elastic Storage System (CVE-2021-3583) Source: CCN Type: IBM Security Bulletin 6610287 (Watson Speech Services Cartridge for Cloud Pak for Data) IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data is vulnerable to injection attacks in Ansible (CVE-2021-3583). Source: CCN Type: WhiteSource Vulnerability Database CVE-2021-3583 | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |