« Volver al listado

CVE-2024-11079

Estado: AplazadaMedia (5.5)—

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-11079",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-11079",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-11-12T14:41:52.352926Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secalert@redhat.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.7,
        "exploitabilityScore": 1.3
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "2.18.0"
            }
          ],
          "packageName": "ansible-core",
          "collectionURL": "https://github.com/ansible/ansible",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_core:2::el8",
            "cpe:/a:redhat:ansible_core:2::el9"
          ],
          "vendor": "Red Hat",
          "product": "Ansible Automation Platform Execution Environments",
          "versions": [
            {
              "status": "unaffected",
              "version": "1.2.0-93",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-automation-platform/ansible-builder-rhel8",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_core:2::el8",
            "cpe:/a:redhat:ansible_core:2::el9"
          ],
          "vendor": "Red Hat",
          "product": "Ansible Automation Platform Execution Environments",
          "versions": [
            {
              "status": "unaffected",
              "version": "3.0.1-108",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-automation-platform/ansible-builder-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_core:2::el8",
            "cpe:/a:redhat:ansible_core:2::el9"
          ],
          "vendor": "Red Hat",
          "product": "Ansible Automation Platform Execution Environments",
          "versions": [
            {
              "status": "unaffected",
              "version": "2.9.27-34",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-automation-platform/ee-29-rhel8",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_core:2::el8",
            "cpe:/a:redhat:ansible_core:2::el9"
          ],
          "vendor": "Red Hat",
          "product": "Ansible Automation Platform Execution Environments",
          "versions": [
            {
              "status": "unaffected",
              "version": "2.12.10-56",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-automation-platform/ee-minimal-rhel8",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_core:2::el8",
            "cpe:/a:redhat:ansible_core:2::el9"
          ],
          "vendor": "Red Hat",
          "product": "Ansible Automation Platform Execution Environments",
          "versions": [
            {
              "status": "unaffected",
              "version": "2.15.13-4",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-automation-platform/ee-minimal-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
            "cpe:/a:redhat:ansible_automation_platform:2.5::el9",
            "cpe:/a:redhat:ansible_automation_platform_developer:2.5::el8",
            "cpe:/a:redhat:ansible_automation_platform_developer:2.5::el9",
            "cpe:/a:redhat:ansible_automation_platform_inside:2.5::el8",
            "cpe:/a:redhat:ansible_automation_platform_inside:2.5::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
          "versions": [
            {
              "status": "unaffected",
              "version": "1:2.16.14-1.el8ap",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-core",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
            "cpe:/a:redhat:ansible_automation_platform:2.5::el9",
            "cpe:/a:redhat:ansible_automation_platform_developer:2.5::el8",
            "cpe:/a:redhat:ansible_automation_platform_developer:2.5::el9",
            "cpe:/a:redhat:ansible_automation_platform_inside:2.5::el8",
            "cpe:/a:redhat:ansible_automation_platform_inside:2.5::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 9",
          "versions": [
            {
              "status": "unaffected",
              "version": "1:2.16.14-1.el9ap",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-core",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/o:redhat:enterprise_linux:10"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 10",
          "packageName": "ansible-core",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:enterprise_linux_ai:1"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux AI (RHEL AI)",
          "packageName": "rhelai1/bootc-azure-nvidia-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:enterprise_linux_ai:1"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux AI (RHEL AI)",
          "packageName": "rhelai1/bootc-nvidia-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-11-12T00:15:15.543",
  "references": [
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:10770",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:11145",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2024-11079",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2325171",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2026/03/msg00006.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks."
    },
    {
      "lang": "es",
      "value": "Se encontró una falla en Ansible-Core. Esta vulnerabilidad permite a los atacantes eludir las protecciones de contenido inseguro mediante el objeto hostvars para hacer referencia y ejecutar contenido con plantilla. Este problema puede provocar la ejecución de código arbitrario si los datos remotos o las salidas de módulos tienen plantillas incorrectas dentro de los playbooks."
    }
  ],
  "lastModified": "2026-06-30T00:16:47.707",
  "sourceIdentifier": "secalert@redhat.com"
}