Code Injection in Ansible - CVE-2023-5764

 

Code Injection in Ansible - CVE-2023-5764

Published: December 13, 2023


Vulnerability identifier: #VU84381
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-5764
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation when handling templates. A remote user can remove the unsafe designation from template data and execute arbitrary code on the system.


Affected software

Ansible
Amazon Linux AMI
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Proxy Module
SUSE Linux Enterprise Micro
SUSE Manager Client Tools Beta for SLE Micro
SUSE Manager Client Tools for SLE Micro
SUSE Linux Enterprise Server for SAP Applications
SUSE Manager Client Tools Beta for SLE
SUSE Manager Client Tools for SLE
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
Fedora
IBM Cloud Pak for Security
IBM Fusion HCI
IBM Watson Discovery for IBM Cloud Pak for Data
QRadar Suite
Siebel CRM Cloud Applications
ansible (Ubuntu package)
mgrctl
mgrctl-bash-completion
mgrctl-zsh-completion
POS_Image-JeOS7
POS_Image-Graphical7
dracut-saltboot
python3x-galaxy-importer (Red Hat package)
python-galaxy-importer (Red Hat package)
golang-github-prometheus-promu
golang-github-prometheus-node_exporter
ansible
ansible-help
ansible-doc
ansible-test
ansible-core
ansible-core (Red Hat package)
python3-spacewalk-koan
spacewalk-koan
mgr-daemon
python3-uyuni-common-libs
uyuni-proxy-systemd-services
python3-spacewalk-check
python3-spacewalk-client-tools
spacewalk-check
python3-spacewalk-client-setup
spacewalk-client-tools
spacewalk-client-setup
spacecmd
supportutils-plugin-susemanager-client
grafana
grafana-debuginfo
IBM Cloud Pak for Watson AIOps

How to mitigate CVE-2023-5764

Install updates from vendor's website.

Ansible - addressed in versions 2.14.12, 2.15.7, 2.16.1
QRadar Suite - update to 1.10.27.0
ansible (Ubuntu package) - update to Ubuntu Pro
mgrctl - update to 0.1.7-159000.3.8.1
mgrctl-bash-completion - update to 0.1.7-159000.3.8.1
mgrctl-zsh-completion - update to 0.1.7-159000.3.8.1
POS_Image-JeOS7 - addressed in versions 0.1.1710765237.46af599-150000.1.21.2, 0.1.1710765237.46af599-159000.3.24.2
POS_Image-Graphical7 - addressed in versions 0.1.1710765237.46af599-150000.1.21.2, 0.1.1710765237.46af599-159000.3.24.2
dracut-saltboot - addressed in versions 0.1.1710765237.46af599-150000.1.53.2, 0.1.1710765237.46af599-159000.3.33.2
python3x-galaxy-importer (Red Hat package) - update to 0.4.18-1.el8ap
python-galaxy-importer (Red Hat package) - update to 0.4.18-1.el9ap
golang-github-prometheus-promu - update to 0.14.0-150000.3.18.2
golang-github-prometheus-node_exporter - update to 1.5.0-159000.6.2.1
IBM Fusion HCI - update to 2.9.0
ansible - addressed in versions 2.9.27-7, 2.9.27-8
ansible-help - update to 2.9.27-7
ansible-doc - update to 2.9.27-8
ansible-test - update to 2.9.27-8
ansible - addressed in versions 2.9.27-150000.1.17.2, 2.9.27-159000.3.12.2
ansible-test - update to 2.9.27-150000.1.17.2
ansible-doc - addressed in versions 2.9.27-150000.1.17.2, 2.9.27-159000.3.12.2
ansible-core - update to 2.15.3-1
ansible-core (Red Hat package) - addressed in versions 2.15.8-1.el8ap, 2.15.8-1.el9ap
ansible-core - addressed in versions 2.16.1-1.fc39, 2.16.1-1.fc40
python3-spacewalk-koan - update to 4.3.6-150000.3.33.2
spacewalk-koan - update to 4.3.6-150000.3.33.2
mgr-daemon - update to 4.3.9-150000.1.47.2
python3-uyuni-common-libs - update to 4.3.10-150000.1.39.2
uyuni-proxy-systemd-services - update to 4.3.12-150000.1.21.2
python3-spacewalk-check - addressed in versions 4.3.19-150000.3.89.2, 5.0.4-159000.6.54.2
python3-spacewalk-client-tools - addressed in versions 4.3.19-150000.3.89.2, 5.0.4-159000.6.54.2
spacewalk-check - addressed in versions 4.3.19-150000.3.89.2, 5.0.4-159000.6.54.2
python3-spacewalk-client-setup - addressed in versions 4.3.19-150000.3.89.2, 5.0.4-159000.6.54.2
spacewalk-client-tools - addressed in versions 4.3.19-150000.3.89.2, 5.0.4-159000.6.54.2
spacewalk-client-setup - addressed in versions 4.3.19-150000.3.89.2, 5.0.4-159000.6.54.2
spacecmd - addressed in versions 4.3.27-150000.3.116.2, 5.0.5-159000.6.48.2
IBM Cloud Pak for Watson AIOps - update to 4.5.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.0
supportutils-plugin-susemanager-client - update to 5.0.3-159000.6.21.2
ansible - addressed in versions 9.1.0-1.fc39, 9.1.0-1.fc40
grafana - addressed in versions 9.5.16-159000.4.30.2, 9.5.18-150000.1.63.2
grafana-debuginfo - addressed in versions 9.5.16-159000.4.30.2, 9.5.18-150000.1.63.2

External References

Related Security Bulletins