You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
ansible/examples
James Cammarata fd30f53289 Fixing security issue with lookup returns not tainting the jinja2 environment
CVE-2017-7481

Lookup returns wrap the result in unsafe, however when used through the
standard templar engine, this does not result in the jinja2 environment being
marked as unsafe as a whole. This means the lookup result looses the unsafe
protection and may become simple unicode strings, which can result in bad
things being re-templated.

This also adds a global lookup param and cfg options for lookups to allow
unsafe returns, so users can force the previous (insecure) behavior.

(cherry picked from commit 72dfb1570d22ac519350a8c09e76c458789120ed)
(cherry picked from commit fadccda7c7a2e8d0650f4dee8e3cea93cf17acfd)
8 years ago
..
playbooks Wrong target for link? 11 years ago
scripts Merge pull request #12363 from breathe/devel 9 years ago
DOCUMENTATION.yml Add github ID to documentation example 9 years ago
ansible.cfg Fixing security issue with lookup returns not tainting the jinja2 environment 8 years ago
hosts comment examples in default hosts file 9 years ago
hosts.yaml draft add group merge priority and yaml inventory 9 years ago