cbcvebase.

Redhat Ansible vulnerabilities

76 known vulnerabilities affecting redhat/ansible.

Total CVEs
76
CISA KEV
0
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL7HIGH25MEDIUM38LOW5UNKNOWN1

Vulnerabilities

Page 2 of 4
CVE-2016-8614P3HIGHCVSS 7.5fixed in 2.2.02018-07-31
CVE-2016-8614 [HIGH] CWE-358 CVE-2016-8614: A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fi A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.
ghsanvdosv
CVE-2019-14846P3HIGHCVSS 7.8≥ 0, < 2.6.20≥ 2.7.0a1, < 2.7.14+1 more2022-05-24
CVE-2019-14846 [HIGH] CWE-117 Ansible Uses Plugins That Disclose Credentials Ansible Uses Plugins That Disclose Credentials Ansible, all ansible_engine-2.x versions and ansible_engine-3.x up to ansible_engine-3.5, was logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.
ghsaosv
CVE-2016-3096P3HIGHCVSS 7.8≤ 1.9.6v2.0+1 more2016-06-03
CVE-2016-3096 [HIGH] CWE-59 CVE-2016-3096: The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0. The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /opt/.lxc-attach-script, (2) the archived container in the archive_path directory, or the (3) lxc-attach-script.log or (4) lxc-attach-script.err files in the
ghsanvdosv
CVE-2014-2686P3HIGHCVSS 7.5fixed in 1.5.42020-01-09
CVE-2014-2686 [HIGH] CWE-670 CVE-2014-2686: Ansible prior to 1.5.4 mishandles the evaluation of some strings. Ansible prior to 1.5.4 mishandles the evaluation of some strings.
ghsanvdosv
CVE-2018-16837P3HIGHCVSS 7.8≥ 2.7.0a1, < 2.7.1≥ 2.6.0a1, < 2.6.7+1 more2022-05-13
CVE-2018-16837 [HIGH] CWE-311 Ansible Leaks Data Passed to ssh-keygen Ansible Leaks Data Passed to ssh-keygen Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.
ghsaosv
CVE-2013-2233P3HIGHCVSS 7.4fixed in 1.2.12018-05-04
CVE-2013-2233 [HIGH] CWE-320 CVE-2013-2233: Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by le Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys.
ghsanvdosv
CVE-2019-14864P3MEDIUMCVSS 6.5≥ 2.7.0, < 2.7.15≥ 2.8.0, < 2.8.7+1 more2020-01-02
CVE-2019-14864 [MEDIUM] CWE-117 CVE-2019-14864: Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, i Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
ghsanvdosv
CVE-2023-5115P3MEDIUMCVSS 6.3≥ 0, < 8.5.02023-12-28
CVE-2023-5115 [MEDIUM] CWE-22 Ansible symlink attack vulnerability Ansible symlink attack vulnerability An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.
ghsaosv
CVE-2019-10217P3MEDIUMCVSS 6.5≥ 2.8.0, < 2.8.42019-11-25
CVE-2019-10217 [MEDIUM] CWE-200 CVE-2019-10217: A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for all gcp modules is not setting no_log to True. Any sensitive data managed by that function would be leak as an output wh
ghsanvdosv
CVE-2021-3583P4HIGHCVSS 7.1≥ 0, < 2.9.23rc1≥ 2.10.0a1, < 2.10.11rc1+1 more2021-09-23
CVE-2021-3583 [HIGH] CWE-20 Improper Input Validation and Command Injection in Ansible Improper Input Validation and Command Injection in Ansible A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows attackers to perform command injection,
ghsaosv
CVE-2019-14856P4MEDIUMCVSS 6.5≥ 2.6.0, < 2.6.20≥ 2.7.0, < 2.7.14+1 more2019-11-26
CVE-2019-14856 [MEDIUM] CWE-287 CVE-2019-14856: ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
ghsanvdosv
CVE-2020-1734P3HIGH≥ 2.10.0a1, < 2.10.0rc1≥ 2.9.0a1, < 2.9.11+1 more2022-02-09
CVE-2020-1734 [HIGH] CWE-78 OS Command Injection in ansible OS Command Injection in ansible A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses `subprocess.Popen()` with `shell=True`, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could take advantage and run arbitrary commands by overwriting the ansible facts.
ghsaosv
CVE-2020-14365P4MEDIUMCVSS 7.1≥ 2.8.0a1, < 2.8.15≥ 2.9.0a1, < 2.9.132021-04-20
CVE-2020-14365 [MEDIUM] CWE-347 Improper Verification of Cryptographic Signature in ansible Improper Verification of Cryptographic Signature in ansible A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when `disable_gpg_check` is set to `False`, which is the default behavior. This flaw leads to malicious packages being installed o
ghsaosv
CVE-2015-6240P4HIGHCVSS 7.8≤ 1.9.12017-06-07
CVE-2015-6240 [HIGH] CWE-59 CVE-2015-6240: The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environment via a symlink attack.
ghsanvdosv
CVE-2019-10206P4MEDIUMCVSS 6.5≥ 2.6.0, < 2.6.19≥ 2.7.0, < 2.7.13+1 more2019-11-22
CVE-2019-10206 [MEDIUM] CWE-522 CVE-2019-10206: ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.
ghsanvdosv
CVE-2024-11079P4MEDIUMCVSS 5.5≥ 0, < 2.10.7+merged+base+2.10.17+dfsg-0+deb11u4≥ 0, < 5.4.0-12024-11-12
CVE-2024-11079 [MEDIUM] CVE-2024-11079: A flaw was found in Ansible-Core A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.
osv
CVE-2020-25636P4HIGHCVSS 7.1v2.10.12020-10-05
CVE-2020-25636 [HIGH] CWE-377 CVE-2020-25636: A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace s A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are written directly to the root bucket, making possible to have collisions when running multiple ansible processes. This issue affects mainly the service availability.
nvd
CVE-2018-10855P4HIGHCVSS 5.9≥ 2.5.0a1, < 2.5.5≥ 2.4.0.0, < 2.4.5.02018-10-10
CVE-2018-10855 [HIGH] CWE-532 Ansible exposes sensitive data in log files and on the terminal Ansible exposes sensitive data in log files and on the terminal Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.
ghsaosv
CVE-2024-9902P4MEDIUMCVSS 6.3≥ 0, < 2.10.7+merged+base+2.10.17+dfsg-0+deb11u2≥ 0, < 5.4.0-12024-11-06
CVE-2024-9902 [MEDIUM] CVE-2024-9902: A flaw was found in Ansible A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged user's home directory. If the unprivileged user has traversal permissions on the directory containing the exploited target file, they retain full control over the conten
osv
CVE-2019-10156P4MEDIUMCVSS 5.4fixed in 2.6.18≥ 2.7.0, < 2.7.12+1 more2019-07-30
CVE-2019-10156 [MEDIUM] CWE-200 CVE-2019-10156: A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.1 A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
ghsanvdosv
Redhat Ansible vulnerabilities | cvebase