Ubuntu Security Notice 6846-1 - It was discovered that Ansible incorrectly handled certain inputs when using tower_callback parameter. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. It was discovered that Ansible incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to perform a Template Injection.
e747cf32a63d2840f3a4cdfe7899ac70ff1c1cdbde760d8373de599f76cf2db8
==========================================================================
Ubuntu Security Notice USN-6846-1
June 25, 2024
ansible vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in Ansible.
Software Description:
- ansible: Configuration management, deployment, and task execution system
Details:
It was discovered that Ansible incorrectly handled certain inputs when using
tower_callback parameter. If a user or an automated system were tricked into
opening a specially crafted input file, a remote attacker could possibly use
this issue to obtain sensitive information. This issue only affected Ubuntu
18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2022-3697)
It was discovered that Ansible incorrectly handled certain inputs. If a user or
an automated system were tricked into opening a specially crafted input file, a
remote attacker could possibly use this issue to perform a Template Injection.
(CVE-2023-5764)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS
ansible 2.10.7+merged+base+2.10.8+dfsg-1ubuntu0.1~esm4
Available with Ubuntu Pro
Ubuntu 20.04 LTS
ansible 2.9.6+dfsg-1ubuntu0.1~esm2
Available with Ubuntu Pro
Ubuntu 18.04 LTS
ansible 2.5.1+dfsg-1ubuntu0.1+esm2
Available with Ubuntu Pro
Ubuntu 16.04 LTS
ansible 2.0.0.2-2ubuntu1.3+esm2
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6846-1
CVE-2022-3697, CVE-2023-5764