Skip to main content

Vendor/product archive

redhat / ansible CVEs

Beta · best-effort

45 CVEs tagged to redhat / ansible5 Critical, 12 High, 22 Medium, 6 Low, 0 Unrated.

CVE-2022-3697

Published Oct 28, 2022

A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take adva…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20180

Published Mar 16, 2022

A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variab…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20191

Published May 26, 2021

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker…

CVSS 5.5 · Medium

CVE-2020-25635

Published Oct 5, 2020

A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed. Files would remain in the bucket e…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25636

Published Oct 5, 2020

A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are written directly to the root bucket, ma…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14904

Published Aug 26, 2020

A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the pro…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2014-4659

Published Feb 20, 2020

Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a f…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4658

Published Feb 20, 2020

The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtain sensitive key information by…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4657

Published Feb 20, 2020

The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-4678

Published Feb 20, 2020

The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE:…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-4660

Published Feb 20, 2020

Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credenti…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4967

Published Feb 18, 2020

Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansible managed host and providing…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-4966

Published Feb 18, 2020

Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which allows remote attackers to exe…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 45 CVEsPage 1 of 2