CVE-2021-3583
CVE-2021-3583 is a high-severity vulnerability in Redhat Ansible Automation Platform with a CVSS 3.x base score of 7.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-94.
Key facts
- Severity: High (CVSS 3.x base score 7.1)
- CVSS v2: 3.6
- EPSS exploit prediction: 1% (58th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-94
- Affected product: Redhat Ansible Automation Platform
- Published:
- Last modified:
Description
A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows attackers to perform command injection, which discloses sensitive information. The highest threat from this vulnerability is to confidentiality and integrity.
Frequently asked questions
- What is CVE-2021-3583?
- A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows attackers to perform command injection, which discloses sensitive information. The highest threat from this vulnerability is to confidentiality and integrity.
- How severe is CVE-2021-3583?
- CVE-2021-3583 has a CVSS 3.x base score of 7.1, rated high severity. It is exploitable over local access with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2021-3583 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (58th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2021-3583?
- CVE-2021-3583 primarily affects Redhat Ansible Automation Platform. In total, 3 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2021-3583?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2021-3583 published?
- CVE-2021-3583 was published on 2021-09-22 and last updated on 2026-06-17.
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1968412
- https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html
Affected products (3)
- cpe:2.3:a:redhat:ansible_automation_platform:1.2:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:*
More vulnerabilities in Redhat Ansible Automation Platform
- CVE-2021-4112 — High (CVSS 8.8): A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw…
- CVE-2026-46625 — High (CVSS 7.5): JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal…
- CVE-2023-50782 — High (CVSS 7.5): A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured…
- CVE-2023-44487 — High (CVSS 7.5): The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset…
- CVE-2021-20228 — High (CVSS 7.5): A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by…
- CVE-2023-4237 — High (CVSS 7.3): A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the…
All CVEs affecting Redhat Ansible Automation Platform →
Other CWE-94 (Code Injection) vulnerabilities
- CVE-2026-105857 — Critical (CVSS 10.0): Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions…
- CVE-2026-55107 — Critical (CVSS 10.0): Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted…
- CVE-2026-96349 — Critical (CVSS 10.0): Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.
- CVE-2026-102425 — Critical (CVSS 10.0): Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa…
- CVE-2026-89275 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…
- CVE-2026-84412 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…