CVE-2014-4966
- EPSS 4.75%
- Veröffentlicht 18.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 02:11:11
Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which allows remote attackers to execute arbitrary code via (1) crafted lookup('pipe') calls or (2) crafted...
CVE-2014-2686
- EPSS 0.38%
- Veröffentlicht 09.01.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 02:06:47
Ansible prior to 1.5.4 mishandles the evaluation of some strings.
CVE-2019-14864
- EPSS 0.94%
- Veröffentlicht 02.01.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:27:31
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This woul...
CVE-2019-14856
- EPSS 0.37%
- Veröffentlicht 26.11.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:27:30
ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
CVE-2019-10217
- EPSS 0.45%
- Veröffentlicht 25.11.2019 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:18:40
A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for all gcp modules is ...
CVE-2019-10206
- EPSS 0.21%
- Veröffentlicht 22.11.2019 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:18:39
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped t...
CVE-2019-10156
- EPSS 0.63%
- Veröffentlicht 30.07.2019 23:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:32
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable su...
CVE-2019-3828
- EPSS 0.04%
- Veröffentlicht 27.03.2019 13:29:01
- Zuletzt bearbeitet 21.11.2024 04:42:37
Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.
CVE-2018-16876
- EPSS 1.03%
- Veröffentlicht 03.01.2019 15:29:01
- Zuletzt bearbeitet 21.11.2024 03:53:30
ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.
CVE-2016-8614
- EPSS 0.08%
- Veröffentlicht 31.07.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 02:59:40
A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.