Redhat Ansible vulnerabilities
76 known vulnerabilities affecting redhat/ansible.
Total CVEs
76
CISA KEV
0
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL7HIGH25MEDIUM38LOW5UNKNOWN1
Vulnerabilities
Page 3 of 4
CVE-2018-16876P4MEDIUMCVSS 5.3≥ 2.5.0, < 2.5.14≥ 2.6.0, < 2.6.11+1 more2019-01-03
CVE-2018-16876 [MEDIUM] CWE-200 CVE-2018-16876: ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+
ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.
ghsanvdosv
CVE-2019-14905P4HIGHCVSS 5.6≥ 2.7.0a1, < 2.7.16≥ 2.8.0a1, < 2.8.8+1 more2021-04-20
CVE-2019-14905 [HIGH] CWE-20 Externally Controlled Reference to a Resource in Another Sphere, Improper Input Validation, and External Control of File Name or Path in Ansible
Externally Controlled Reference to a Resource in Another Sphere, Improper Input Validation, and External Control of File Name or Path in Ansible
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used t
ghsaosv
CVE-2020-1753P4MEDIUMCVSS 5.5≥ 2.7.0a1, < 2.7.18≥ 2.8.0a1, < 2.8.12+1 more2021-04-07
CVE-2020-1753 [MEDIUM] CWE-200 Insertion of Sensitive Information into Log File, Invocation of Process Using Visible Sensitive Information, and Exposure of Sensitive Information to an Unauthorized Actor in Ansible
Insertion of Sensitive Information into Log File, Invocation of Process Using Visible Sensitive Information, and Exposure of Sensitive Information to an Unauthorized Actor in Ansible
A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible
ghsaosv
CVE-2020-10685P4MEDIUMCVSS 5.5≥ 2.7.0a1, < 2.7.17≥ 2.8.0a1, < 2.8.11+1 more2021-04-07
CVE-2020-10685 [MEDIUM] CWE-377 Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible
Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible
A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when using modules which decrypts vault files such as assemble, script, unarchive, win_copy, aws_s
ghsaosv
CVE-2021-20191P4MEDIUMCVSS 5.5fixed in 2.8.19≥ 2.9.0, < 2.9.18+2 more2021-05-26
CVE-2021-20191 [MEDIUM] CWE-532 CVE-2021-20191: A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by def
A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are
ghsanvdosv
CVE-2021-20178P4MEDIUMCVSS 5.5fixed in 2.9.18vbefore 2.9.182021-05-26
CVE-2021-20178 [MEDIUM] CWE-532 CVE-2021-20178: A flaw was found in ansible module where credentials are disclosed in the console log by default and
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality.
ghsanvdosv
CVE-2021-20180P4MEDIUMCVSS 5.5fixed in 2.9.18vFixed in ansible 2.9.182022-03-16
CVE-2021-20180 [MEDIUM] CWE-532 CVE-2021-20180: A flaw was found in ansible module where credentials are disclosed in the console log by default and
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality.
ghsanvdosv
CVE-2024-8775P4MEDIUMCVSS 5.5≥ 0, < 2.10.7+merged+base+2.10.17+dfsg-0+deb11u2≥ 0, < 5.4.0-12024-09-14
CVE-2024-8775 [MEDIUM] CVE-2024-8775: A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook
A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_log: true parameter, resulting in sensitive data being printed
osv
CVE-2025-14010P4MEDIUMCVSS 5.5≥ 0, < 12.2.02025-12-04
CVE-2025-14010 [MEDIUM] CWE-200 Ansible Community General Collection is vulnerable to exposure of sensitive information
Ansible Community General Collection is vulnerable to exposure of sensitive information
A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets
ghsaosv
CVE-2021-3447P4MEDIUMCVSS 5.5fixed in 1.2.2vRed Hat Ansible Automation Platform 1.2.2, Ansible Tower 3.8.22021-04-01
CVE-2021-3447 [MEDIUM] CWE-532 CVE-2021-3447: A flaw was found in several ansible modules, where parameters containing credentials, such as secret
A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nodes, as well as being made visible on the controller node when run in verbose mode. These parameters were not protected by the no_log feature. An attacker can take advantage of this information to steal th
nvdosv
CVE-2020-14330P4MEDIUMCVSS 5.5≥ 0, < 2.10.02022-02-09
CVE-2020-14330 [MEDIUM] CWE-116 Improper Output Neutralization and Improper Encoding or Escaping of Output for Logs in ansible
Improper Output Neutralization and Improper Encoding or Escaping of Output for Logs in ansible
An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed tasks to read keys used in playbooks from other u
ghsaosv
CVE-2020-10729P4MEDIUMCVSS 5.5≥ 0, < 2.9.62021-06-15
CVE-2020-10729 [MEDIUM] CWE-330 Insufficiently random values in Ansible
Insufficiently random values in Ansible
A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as the template caching action for the same file since no re-evaluation happens. The highest threat from this vulnerability would be that all passwords are exposed at once for the file. This flaw affects Ansible Engine versions before 2.9.6.
ghsaosv
CVE-2020-14332P4MEDIUMCVSS 5.5≥ 0, < 2.8.14≥ 2.9.0a1, < 2.9.12+1 more2022-02-09
CVE-2020-14332 [MEDIUM] CWE-117 Insertion of Sensitive Information into Log File and Improper Output Neutralization for Logs in ansible
Insertion of Sensitive Information into Log File and Improper Output Neutralization for Logs in ansible
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from th
ghsaosv
CVE-2020-25635P4MEDIUMCVSS 5.5v2.10.12020-10-05
CVE-2020-25635 [MEDIUM] CWE-212 CVE-2020-25635: A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is no
A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed. Files would remain in the bucket exposing the data. This issue affects directly data confidentiality.
ghsanvdosv
CVE-2019-14858P4MEDIUMCVSS 5.5≥ 2.9.0a1, < 2.9.0rc4≥ 2.8.0a1, < 2.8.6+2 more2022-05-24
CVE-2019-14858 [MEDIUM] CWE-532 Ansible leaks sensitive information to logs when told not to
Ansible leaks sensitive information to logs when told not to
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as `no_log`, passing an invalid parameter name to the module will cause the task to fail before the `no_log` options in the sub parameters are processed. As a result, data in the sub parameter
ghsaosv
CVE-2016-8647P4MEDIUMCVSS 4.9≥ 0, < 2.2.1.02018-10-10
CVE-2016-8647 [MEDIUM] CWE-20 Improper Input Validation in ansible
Improper Input Validation in ansible
An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed.
ghsaosv
CVE-2021-3620P4MEDIUMCVSS 5.5≥ 0, < 2.9.272022-03-04
CVE-2021-3620 [MEDIUM] CWE-209 Ansible discloses sensitive information in traceback error message
Ansible discloses sensitive information in traceback error message
Ansible is an IT automation system that handles configuration management, application deployment, cloud provisioning, ad-hoc task execution, network automation, and multi-node orchestration. A flaw was found in Ansible Engine's ansible-connection module where sensitive information, such as the Ansible user credentials, is disclosed
ghsaosv
CVE-2024-0690P4MEDIUMCVSS 5.5fixed in 2.14.4≥ 2.15.0, < 2.15.9+1 more2024-02-06
CVE-2024-0690 [MEDIUM] CWE-117 CVE-2024-0690: An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
nvdosv
CVE-2020-1746P4MEDIUMCVSS 5.0≥ 2.8.0a1, < 2.8.11≥ 2.9.0a1, < 2.9.7+1 more2021-04-20
CVE-2020-1746 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in ansible
Exposure of Sensitive Information to an Unauthorized Actor in ansible
A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when the ldap_attr and ldap_entry community modules are used. The issue discloses the LDAP bind password to
ghsaosv
CVE-2014-4660P4MEDIUMCVSS 5.5fixed in 1.5.52020-02-20
CVE-2014-4660 [MEDIUM] CWE-522 CVE-2014-4660: Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb li
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb http://user:pass@server:port/" format.
ghsanvdosv