Red Hat Ansible vulnerabilities

29 known vulnerabilities affecting red_hat/ansible.

Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH5MEDIUM20LOW3

Vulnerabilities

Page 2 of 2
CVE-2019-14858MEDIUMCVSS 5.5vansible_engine-2.x up to 2.8vansible_tower-3.x up to 3.52019-10-14
CVE-2019-14858 [MEDIUM] CWE-117 CVE-2019-14858: A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a mo A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields wi
cvelistv5nvd
CVE-2019-14846HIGHCVSS 7.8vall ansible_engine-2.x and ansible_engine-3.x up to ansible_engine-3.52019-10-08
CVE-2019-14846 [HIGH] CWE-117 CVE-2019-14846: In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-e In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.
cvelistv5nvd
CVE-2019-10156MEDIUMCVSS 5.4vfixed in 2.6.18vfixed in 2.7.12+1 more2019-07-30
CVE-2019-10156 [MEDIUM] CWE-200 CVE-2019-10156: A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.1 A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
cvelistv5nvd
CVE-2019-3828MEDIUMCVSS 4.2v2.5.15v2.6.14+1 more2019-03-27
CVE-2019-3828 [MEDIUM] CWE-22 CVE-2019-3828: Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.
cvelistv5nvd
CVE-2018-16876MEDIUMCVSS 5.3vbefore 2.5.14vbefore 2.6.11+1 more2019-01-03
CVE-2018-16876 [MEDIUM] CWE-200 CVE-2018-16876: ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.
cvelistv5nvd
CVE-2018-16859MEDIUMCVSS 4.4v2.8 and older2018-11-29
CVE-2018-16859 [MEDIUM] CWE-532 CVE-2018-16859: Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module l Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. Ansible Engine 2.8 and older are believed to be vul
cvelistv5nvd
CVE-2016-8628CRITICALCVSS 9.1v2.2.02018-07-31
CVE-2016-8628 [CRITICAL] CWE-77 CVE-2016-8628: Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible control Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the user Ansible runs as.
cvelistv5nvd
CVE-2016-8614HIGHCVSS 7.5v2.2.02018-07-31
CVE-2016-8614 [HIGH] CWE-358 CVE-2016-8614: A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fi A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.
cvelistv5nvd
CVE-2016-8647MEDIUMCVSS 4.9v2.2.1.02018-07-26
CVE-2016-8647 [MEDIUM] CWE-20 CVE-2016-8647: An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed.
cvelistv5nvd