{"id":"CVE-2023-5764","aliases":["GHSA-7j69-qfc3-2fq9","PYSEC-2026-1122"],"url":"https://o3.security/vulnerability/CVE-2023-5764","summary":"Ansible: template injection","details":"A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.","published":"2023-12-12T22:01:33.467Z","modified":"2026-08-12T03:51:46.224699110Z","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"ansible-core","fixedVersion":"2.16.1"},{"ecosystem":"PyPI","name":"ansible-core","fixedVersion":"2.15.8"},{"ecosystem":"PyPI","name":"ansible-core","fixedVersion":"2.14.12"}],"fix":null,"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X7Q6CHPVCHMZS5M7V22GOKFSXZAQ24EU/"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2023:7773"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2023-5764"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/5xxx/CVE-2023-5764.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-5764"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20241025-0001/"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2247629"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:46.224699110Z"}}