Redhat

Ansible

55 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 22.07.2026 12:06:48
  • Zuletzt bearbeitet 22.07.2026 16:23:35

A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traversal, allows an attacker to manipulate an AI agent through indirect prompt injection. By doing so, the attacker can cause the serve...

  • EPSS 0.75%
  • Veröffentlicht 22.07.2026 12:06:42
  • Zuletzt bearbeitet 23.07.2026 14:17:14

A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the `ansible.python.activati...

  • EPSS 0.32%
  • Veröffentlicht 21.07.2026 17:26:14
  • Zuletzt bearbeitet 22.07.2026 15:16:53

A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator before user-supplied URLs when installing collections...

  • EPSS 0.33%
  • Veröffentlicht 19.06.2026 18:49:55
  • Zuletzt bearbeitet 22.06.2026 18:33:17

A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller stores the pull_request.statuses_url value from the webhook payload without validating that it points to a trusted GitHub API endpoin...

  • EPSS 0.33%
  • Veröffentlicht 15.04.2025 05:55:26
  • Zuletzt bearbeitet 30.06.2026 01:16:26

A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 colli...

  • EPSS 0.5%
  • Veröffentlicht 12.11.2024 00:15:15
  • Zuletzt bearbeitet 30.06.2026 00:16:47

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module ...

  • EPSS 0.26%
  • Veröffentlicht 06.11.2024 10:15:06
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against th...

  • EPSS 0.27%
  • Veröffentlicht 14.09.2024 03:15:08
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_...

  • EPSS 0.38%
  • Veröffentlicht 25.04.2024 17:15:48
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rulebook data f...

  • EPSS 1.53%
  • Veröffentlicht 21.03.2024 13:00:08
  • Zuletzt bearbeitet 21.08.2026 12:16:15

A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. Th...