Debian Ansible vulnerabilities
66 known vulnerabilities affecting debian/ansible.
Total CVEs
66
CISA KEV
0
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH16MEDIUM30LOW15
Vulnerabilities
Page 4 of 4
CVE-2014-4658P4MEDIUMCVSS 5.5fixed in ansible 1.5.5+dfsg-1 (bookworm)2014
CVE-2014-4658 [MEDIUM] CVE-2014-4658: ansible - The vault subsystem in Ansible before 1.5.5 does not set the umask before creati...
The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtain sensitive key information by reading a file.
Scope: local
bookworm: resolved (fixed in 1.5.5+dfsg-1)
bullseye: resolved (fixed in 1.5.5+dfsg-1)
forky: resolved (fixed in 1.5.5+dfsg-1)
sid: resolved (fixed in 1.5.5+dfs
debian
CVE-2014-4659P4MEDIUMCVSS 5.5fixed in ansible 1.5.5+dfsg-1 (bookworm)2014
CVE-2014-4659 [MEDIUM] CVE-2014-4659: ansible - Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow l...
Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.
Scope: local
bookworm: resolved (fixed in 1.5.5+dfsg-1)
bullseye: resolved (fixed in 1.5.5+dfsg-1)
forky: resolved (fixed in 1.
debian
CVE-2020-1735P4MEDIUMCVSS 4.2fixed in ansible 2.9.7+dfsg-1 (bookworm)2020
CVE-2020-1735 [MEDIUM] CVE-2020-1735: ansible - A flaw was found in the Ansible Engine when the fetch module is used. An attacke...
A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
Scope: local
bookworm: resolved (fixed in 2.9.7+dfsg-1)
bullseye: resolved (fixed in 2.9.7+dfsg-1
debian
CVE-2019-3828P4MEDIUMCVSS 4.2fixed in ansible 2.7.7+dfsg-1 (bookworm)2019
CVE-2019-3828 [MEDIUM] CVE-2019-3828: ansible - Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal ...
Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.
Scope: local
bookworm: resolved (fixed in 2.7.7+dfsg-1)
bullseye: resolved (fixed in 2.7.7+dfsg-1)
forky: resolved (fix
debian
CVE-2020-1739P4LOWCVSS 3.9fixed in ansible 2.9.7+dfsg-1 (bookworm)2020
CVE-2020-1739 [LOW] CVE-2020-1739: ansible - A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and pri...
A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.
Scope: local
bookworm: resolved (fixed i
debian
CVE-2013-4259P4LOWCVSS 1.9fixed in ansible 1.3.4+dfsg-1 (bookworm)2013
CVE-2013-4259 [LOW] CVE-2013-4259: ansible - runner/connection_plugins/ssh.py in Ansible before 1.2.3, when using ControlPers...
runner/connection_plugins/ssh.py in Ansible before 1.2.3, when using ControlPersist, allows local users to redirect a ssh session via a symlink attack on a socket file with a predictable name in /tmp/.
Scope: local
bookworm: resolved (fixed in 1.3.4+dfsg-1)
bullseye: resolved (fixed in 1.3.4+dfsg-1)
forky: resolved (fixed in 1.3.4+dfsg-1)
sid: resolved (fixed in 1.3.4+
debian
← Previous4 / 4