Description

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.

INFO

Published Date :

2024-11-11T23:32:55.539Z

Last Modified :

2026-03-18T01:33:55.730Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2024-11079 vulnerability.

Vendors Products
Redhat
  • Ansible Automation Platform
  • Ansible Automation Platform Developer
  • Ansible Automation Platform Inside
  • Ansible Core
  • Enterprise Linux
  • Enterprise Linux Ai

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact