CVE-2020-10684
- EPSS 0.02%
- Published 24.03.2020 14:15:12
- Last modified 21.11.2024 04:55:50
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts...
CVE-2020-1738
- EPSS 0.14%
- Published 16.03.2020 16:15:14
- Last modified 21.11.2024 05:11:16
A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file...
CVE-2020-1740
- EPSS 0.04%
- Published 16.03.2020 16:15:14
- Last modified 21.11.2024 05:11:17
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp a...
CVE-2020-1735
- EPSS 0.14%
- Published 16.03.2020 16:15:13
- Last modified 21.11.2024 05:11:16
A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believ...
CVE-2020-1736
- EPSS 0.04%
- Published 16.03.2020 16:15:13
- Last modified 21.11.2024 05:11:16
A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be ...
CVE-2020-1739
- EPSS 0.04%
- Published 12.03.2020 18:15:12
- Last modified 21.11.2024 05:11:16
A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could ta...
- EPSS 0.04%
- Published 11.03.2020 19:15:13
- Last modified 21.11.2024 05:11:16
A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in ...
CVE-2012-6685
- EPSS 0.32%
- Published 19.02.2020 15:15:11
- Last modified 21.11.2024 01:46:40
Nokogiri before 1.5.4 is vulnerable to XXE attacks
- EPSS 0.65%
- Published 11.02.2020 20:15:11
- Last modified 21.11.2024 05:11:13
An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an iscsi_co_block_s...
CVE-2015-5741
- EPSS 1.75%
- Published 08.02.2020 19:15:10
- Last modified 21.11.2024 02:33:45
The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contains Content-Length and Transfer-Encoding header fiel...