High severity8.8NVD Advisory· Published Aug 28, 2023· Updated Jun 17, 2026
CVE-2023-39059
CVE-2023-39059
Description
An issue in ansible semaphore v.2.8.90 allows a remote attacker to execute arbitrary code via a crafted payload to the extra variables parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/ansible-semaphore/semaphoreGo | <= 2.8.90 | — |
Affected products
2- ansible/semaphoredescription
Patches
Vulnerability mechanics
References
5- www.alevsk.com/2023/07/a-quick-story-of-security-pitfalls-with-execcommand-in-software-integrations/nvdExploitThird Party Advisory
- gist.github.com/Alevsk/1757da24c5fb8db735d392fd4146ca3anvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-3r32-cp7v-5wq4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-39059ghsaADVISORY
- www.alevsk.com/2023/07/a-quick-story-of-security-pitfalls-with-execcommand-in-software-integrationsghsaWEB
News mentions
0No linked articles in our index yet.