Redhat

Ansible

51 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 15.04.2025 05:55:26
  • Zuletzt bearbeitet 02.09.2025 10:15:34

A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 colli...

  • EPSS 0.39%
  • Veröffentlicht 12.11.2024 00:15:15
  • Zuletzt bearbeitet 18.12.2024 04:15:06

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module ...

  • EPSS 0.05%
  • Veröffentlicht 06.11.2024 10:15:06
  • Zuletzt bearbeitet 25.02.2025 20:15:36

A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against th...

  • EPSS 0.03%
  • Veröffentlicht 14.09.2024 03:15:08
  • Zuletzt bearbeitet 10.02.2025 19:15:39

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_...

  • EPSS 0.08%
  • Veröffentlicht 25.04.2024 17:15:48
  • Zuletzt bearbeitet 21.11.2024 08:51:01

A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rulebook data f...

  • EPSS 1.02%
  • Veröffentlicht 21.03.2024 13:00:08
  • Zuletzt bearbeitet 13.05.2025 09:15:19

A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. Th...

  • EPSS 0.06%
  • Veröffentlicht 06.02.2024 12:15:55
  • Zuletzt bearbeitet 17.01.2025 20:15:27

An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this iss...

  • EPSS 0.07%
  • Veröffentlicht 12.12.2023 22:15:22
  • Zuletzt bearbeitet 21.11.2024 08:42:26

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating i...

  • EPSS 0.11%
  • Veröffentlicht 28.10.2022 16:15:16
  • Zuletzt bearbeitet 21.11.2024 07:20:03

A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely,...

  • EPSS 0.06%
  • Veröffentlicht 16.03.2022 15:15:09
  • Zuletzt bearbeitet 21.11.2024 05:46:04

A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline cre...