Search CVE reports


Toggle filters

11 – 20 of 87 results


CVE-2023-5189

Medium priority
Needs evaluation

A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy importer of Ansible Automation Hub, a symlink could be dropped on the...

2 affected packages

ansible, ansible-core

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ansible-core Needs evaluation Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2023-4380

Medium priority
Needs evaluation

A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting...

2 affected packages

ansible, ansible-core

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ansible-core Needs evaluation Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2023-4237

Medium priority
Needs evaluation

A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files,...

2 affected packages

ansible, ansible-core

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ansible-core Needs evaluation Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2023-4567

Medium priority
Ignored

Rejected reason: Issue has been found to be non-reproducible, therefore not a viable flaw.

2 affected packages

ansible, ansible-core

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Not affected
ansible-core Not affected Not in release Not in release
Show less packages

CVE-2022-3697

Medium priority

Some fixes available 3 of 14

A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the...

2 affected packages

ansible, ansible-core

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Fixed Fixed Fixed
ansible-core Needs evaluation Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2021-4041

Medium priority

Some fixes available 1 of 2

A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters getting executed as host's shell command. A developer...

1 affected package

ansible-runner

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible-runner Fixed Not in release Not in release
Show less packages

CVE-2021-3702

High priority
Ignored

A race condition flaw was found in ansible-runner, where an attacker could watch for rapid creation and deletion of a temporary directory, substitute their directory at that name, and then have access to...

1 affected package

ansible-runner

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible-runner Not affected Not in release Not in release
Show less packages

CVE-2021-3701

High priority
Ignored

A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world R/W locations. This flaw allows an attacker to pre-create the directory, resulting in reading private...

1 affected package

ansible-runner

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible-runner Not affected Not in release Not in release
Show less packages

CVE-2022-2568

Medium priority
Needs evaluation

A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remove...

3 affected packages

ansible, ansible-base, ansible-core

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ansible-base Not in release Not in release Not in release Not in release Not in release
ansible-core Needs evaluation Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2021-20180

Medium priority
Needs evaluation

A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal...

1 affected package

ansible

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages