cbcvebase.

Redhat Ansible Engine vulnerabilities

25 known vulnerabilities affecting redhat/ansible_engine.

Total CVEs
25
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH9MEDIUM14

Vulnerabilities

Page 2 of 2
CVE-2016-8647P4MEDIUMCVSS 4.9fixed in 2.2.1.02018-07-26
CVE-2016-8647 [MEDIUM] CWE-20 CVE-2016-8647: An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed.
nvd
CVE-2021-3620P4MEDIUMCVSS 5.5fixed in 2.9.272022-03-03
CVE-2021-3620 [MEDIUM] CWE-209 CVE-2021-3620: A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
nvd
CVE-2020-1746P4MEDIUMCVSS 5.0≥ 2.7.0, < 2.7.17≥ 2.8.0, < 2.8.11+1 more2020-05-12
CVE-2020-1746 [MEDIUM] CWE-200 CVE-2020-1746: A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8 A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when the ldap_attr and ldap_entry community modules are used. The issue discloses the LDAP bind password to stdout or a log file if
nvd
CVE-2020-10691P4MEDIUMCVSS 5.2≥ 2.9.0, < 2.9.72020-04-30
CVE-2020-10691 [MEDIUM] CWE-22 CVE-2020-10691: An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when runnin An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.
nvd
CVE-2018-16859P4MEDIUMCVSS 4.4fixed in 2.5.13≥ 2.6.0, < 2.6.10+2 more2018-11-29
CVE-2018-16859 [MEDIUM] CWE-532 CVE-2018-16859: Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module l Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. Ansible Engine 2.8 and older are believed to be vul
nvd
Redhat Ansible Engine vulnerabilities | cvebase