{
  "threat_severity" : "Moderate",
  "public_date" : "2017-05-09T00:00:00Z",
  "bugzilla" : {
    "description" : "ansible: Security issue with lookup return not tainting the jinja2 environment",
    "id" : "1450018",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1450018"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.3",
    "cvss3_scoring_vector" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-20",
  "details" : [ "Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not evaluated.", "An input validation flaw was found in Ansible, where it fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not evaluated." ],
  "acknowledgement" : "This issue was discovered by Evgeni Golov (Red Hat).",
  "affected_release" : [ {
    "product_name" : "Red Hat Gluster Storage 3.2 for RHEL 7",
    "release_date" : "2017-05-25T00:00:00Z",
    "advisory" : "RHSA-2017:1334",
    "cpe" : "cpe:/a:redhat:storage:3.2:server:el7",
    "package" : "ansible-0:2.2.3.0-1.el7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.2",
    "release_date" : "2017-05-17T00:00:00Z",
    "advisory" : "RHSA-2017:1244",
    "cpe" : "cpe:/a:redhat:openshift:3.2::el7",
    "package" : "ansible-0:2.2.3.0-1.el7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.2",
    "release_date" : "2017-05-17T00:00:00Z",
    "advisory" : "RHSA-2017:1244",
    "cpe" : "cpe:/a:redhat:openshift:3.2::el7",
    "package" : "openshift-ansible-0:3.2.56-1.git.0.b844ab7.el7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.3",
    "release_date" : "2017-05-17T00:00:00Z",
    "advisory" : "RHSA-2017:1244",
    "cpe" : "cpe:/a:redhat:openshift:3.3::el7",
    "package" : "ansible-0:2.2.3.0-1.el7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.3",
    "release_date" : "2017-05-17T00:00:00Z",
    "advisory" : "RHSA-2017:1244",
    "cpe" : "cpe:/a:redhat:openshift:3.3::el7",
    "package" : "openshift-ansible-0:3.3.82-1.git.0.af0c922.el7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.4",
    "release_date" : "2017-05-17T00:00:00Z",
    "advisory" : "RHSA-2017:1244",
    "cpe" : "cpe:/a:redhat:openshift:3.4::el7",
    "package" : "ansible-0:2.2.3.0-1.el7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.4",
    "release_date" : "2017-05-17T00:00:00Z",
    "advisory" : "RHSA-2017:1244",
    "cpe" : "cpe:/a:redhat:openshift:3.4::el7",
    "package" : "openshift-ansible-0:3.4.89-1.git.0.ac29ce8.el7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.5",
    "release_date" : "2017-05-17T00:00:00Z",
    "advisory" : "RHSA-2017:1244",
    "cpe" : "cpe:/a:redhat:openshift:3.5::el7",
    "package" : "ansible-0:2.2.3.0-1.el7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.5",
    "release_date" : "2017-05-17T00:00:00Z",
    "advisory" : "RHSA-2017:1244",
    "cpe" : "cpe:/a:redhat:openshift:3.5::el7",
    "package" : "openshift-ansible-0:3.5.71-1.git.0.128c2db.el7"
  }, {
    "product_name" : "Red Hat OpenStack Platform 10.0 (Newton)",
    "release_date" : "2017-06-28T00:00:00Z",
    "advisory" : "RHSA-2017:1599",
    "cpe" : "cpe:/a:redhat:openstack:10::el7",
    "package" : "ansible-0:2.2.3.0-1.el7"
  }, {
    "product_name" : "Red Hat OpenStack Platform 11.0 (Ocata)",
    "release_date" : "2017-06-15T00:00:00Z",
    "advisory" : "RHSA-2017:1476",
    "cpe" : "cpe:/a:redhat:openstack:11::el7",
    "package" : "ansible-0:2.2.3.0-1.el7"
  }, {
    "product_name" : "Red Hat Storage Console 2 for Red Hat Enteprise Linux 7",
    "release_date" : "2017-06-19T00:00:00Z",
    "advisory" : "RHSA-2017:1499",
    "cpe" : "cpe:/a:redhat:rhscon:2::el7",
    "package" : "ansible-0:2.2.3.0-1.el7"
  }, {
    "product_name" : "Red Hat Virtualization Engine 4.1",
    "release_date" : "2017-08-22T00:00:00Z",
    "advisory" : "RHSA-2017:2524",
    "cpe" : "cpe:/a:redhat:rhev_manager:4",
    "package" : "ansible-0:2.3.1.0-3.el7"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat OpenStack Platform 12 (Pike)",
    "fix_state" : "Not affected",
    "package_name" : "ansible",
    "cpe" : "cpe:/a:redhat:openstack:12"
  }, {
    "product_name" : "Red Hat Quickstart Cloud Installer 1",
    "fix_state" : "Affected",
    "package_name" : "ansible",
    "cpe" : "cpe:/a:redhat:qci:1.0::el7"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2017-7481\nhttps://nvd.nist.gov/vuln/detail/CVE-2017-7481" ],
  "name" : "CVE-2017-7481",
  "csaw" : false
}