Redhat Ansible Engine vulnerabilities
25 known vulnerabilities affecting redhat/ansible_engine.
Total CVEs
25
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH9MEDIUM14
Vulnerabilities
Page 1 of 2
CVE-2017-7481P3CRITICALCVSS 9.8Exploitedfixed in 2.3.1.0≥ 2.3.2.0, < 2.4.0.02018-07-19
CVE-2017-7481 [CRITICAL] CWE-20 CVE-2017-7481: Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe.
Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not eval
nvd
CVE-2018-7750P2CRITICALCVSS 9.8PoCv2.0v2.42018-03-13
CVE-2018-7750 [CRITICAL] CWE-287 CVE-2018-7750: transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client ca
nvd
CVE-2021-20228P3HIGHCVSS 7.5v2.9.18v2.0+2 more2021-04-29
CVE-2021-20228 [HIGH] CWE-200 CVE-2021-20228: A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is
A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.
nvd
CVE-2018-10875P3HIGHCVSS 7.8v2.0v2.4+2 more2018-07-13
CVE-2018-10875 [HIGH] CWE-426 CVE-2018-10875: A flaw was found in ansible. ansible.cfg is read from the current working directory which can be alt
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.
nvd
CVE-2018-10874P3HIGHCVSS 7.8v2.0v2.4+2 more2018-07-02
CVE-2018-10874 [HIGH] CWE-426 CVE-2018-10874: In ansible it was found that inventory variables are loaded from current working directory when runn
In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.
nvd
CVE-2020-1737P3HIGHCVSS 7.8fixed in 2.7.17≥ 2.8.0, < 2.8.9+1 more2020-03-09
CVE-2020-1737 [HIGH] CWE-22 CVE-2020-1737: A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Ex
A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This i
nvd
CVE-2019-14846P3HIGHCVSS 7.8fixed in 2.6.20≥ 2.7.0, < 2.7.14+3 more2019-10-08
CVE-2019-14846 [HIGH] CWE-117 CVE-2019-14846: In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-e
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.
nvd
CVE-2018-16837P3HIGHCVSS 7.8v2.0v2.5+2 more2018-10-23
CVE-2018-16837 [HIGH] CWE-214 CVE-2018-16837: Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lea
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.
nvd
CVE-2020-1734P3HIGHCVSS 7.4≤ 2.7.16v2.8.8+1 more2020-03-03
CVE-2020-1734 [HIGH] CWE-78 CVE-2020-1734: A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe
A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could take advantage and run arbitrary commands by overwriting the ansible facts.
nvd
CVE-2021-3583P4HIGHCVSS 7.1fixed in 2.9.232021-09-22
CVE-2021-3583 [HIGH] CWE-20 CVE-2021-3583: A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This iss
A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows attackers to perform command injection, whi
nvd
CVE-2020-14365P4HIGHCVSS 7.1≥ 2.8.0, ≤ 2.8.15≥ 2.9.0, ≤ 2.9.13+1 more2020-09-23
CVE-2020-14365 [HIGH] CWE-347 CVE-2020-14365: A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9
A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the syst
nvd
CVE-2018-10855P4MEDIUMCVSS 5.9≥ 2.4, < 2.4.5≤ 2.5.5+1 more2018-07-03
CVE-2018-10855 [MEDIUM] CWE-532 CVE-2018-10855: Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tas
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.
nvd
CVE-2018-16876P4MEDIUMCVSS 5.3v2.0v2.5+2 more2019-01-03
CVE-2018-16876 [MEDIUM] CWE-200 CVE-2018-16876: ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+
ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.
nvd
CVE-2019-14905P4MEDIUMCVSS 5.6≥ 2.7.0, < 2.7.16≥ 2.8.0, < 2.8.8+1 more2020-03-31
CVE-2019-14905 [MEDIUM] CWE-20 CVE-2019-14905: A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x b
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of con
nvd
CVE-2020-1753P4MEDIUMCVSS 5.5fixed in 2.7.18≥ 2.8.0, < 2.8.11+1 more2020-03-16
CVE-2020-1753 [MEDIUM] CWE-200 CVE-2020-1753: A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible
A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2.9.x versions prior to 2.9.7, when managing kubernetes using the k8s module. Sensitive parameters such as passwords and tokens are passed to kubectl from the command line, not using an environment variabl
nvd
CVE-2020-10685P4MEDIUMCVSS 5.5≥ 2.7.0, < 2.7.17≥ 2.8.0, < 2.8.11+1 more2020-05-11
CVE-2020-10685 [MEDIUM] CWE-459 CVE-2020-10685: A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x b
A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when using modules which decrypts vault files such as assemble, script, unarchive, win_copy, aws_s3 or copy modules. The temporary dir
nvd
CVE-2020-14330P4MEDIUMCVSS 5.5fixed in 2.9.122020-09-11
CVE-2020-14330 [MEDIUM] CWE-532 CVE-2020-14330: An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, wher
An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed tasks to read keys used in playbooks from other users within the uri module. The highest threat from this vulnerability is
nvd
CVE-2020-10729P4MEDIUMCVSS 5.5fixed in 2.9.6vansible-engine 2.9.62021-05-27
CVE-2020-10729 [MEDIUM] CWE-330 CVE-2020-10729: A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups
A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as the template caching action for the same file since no re-evaluation happens. The highest threat from this vulnerability would be that all passwords are exposed at once for the file. This flaw affects Ansi
nvd
CVE-2020-14332P4MEDIUMCVSS 5.5≥ 2.8.0, < 2.8.14≥ 2.9.0, < 2.9.122020-09-11
CVE-2020-14332 [MEDIUM] CWE-117 CVE-2020-14332: A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--che
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.
nvd
CVE-2019-14858P4MEDIUMCVSS 5.5≥ 2.0, ≤ 2.8.02019-10-14
CVE-2019-14858 [MEDIUM] CWE-117 CVE-2019-14858: A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a mo
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields wi
nvd
1 / 2Next →