Redhat Ansible Automation Platform vulnerabilities
23 known vulnerabilities affecting redhat/ansible_automation_platform.
Total CVEs
23
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH7MEDIUM14LOW2
Vulnerabilities
Page 2 of 2
CVE-2021-3681MEDIUMCVSS 5.5v1.22022-04-18
CVE-2021-3681 [MEDIUM] CWE-522 CVE-2021-3681: A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in th
A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly excluded via the ``build_ignore`` list in "galaxy.yml" include files in the ``.tar.gz`` file. This contains sensitive info, such as the user's Ansible Galaxy API key and any secrets in ``ansible`` or ``ansi
nvd
CVE-2021-3583HIGHCVSS 7.1v1.22021-09-22
CVE-2021-3583 [HIGH] CWE-20 CVE-2021-3583: A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This iss
A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows attackers to perform command injection, whi
nvd
CVE-2021-20228HIGHCVSS 7.5v1.22021-04-29
CVE-2021-20228 [HIGH] CWE-200 CVE-2021-20228: A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is
A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.
nvd
← Previous2 / 2