CVE-2017-7481
Publication date 19 July 2018
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not evaluated.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| ansible | ||
| 24.04 LTS noble |
Not affected
|
|
| 22.04 LTS jammy |
Not affected
|
|
| 20.04 LTS focal |
Not affected
|
|
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Fixed 2.0.0.2-2ubuntu1.3
|
|
| 14.04 LTS trusty |
Not affected
|
Notes
Severity score breakdown
CVSS version: CVSS v3.0
Base score
9.8 · Critical
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
Related Ubuntu Security Notices (USN)
- USN-4072-1
- Ansible vulnerabilities
- 24 July 2019