CVE-2020-1736
- EPSS 0.04%
- Published 16.03.2020 16:15:13
- Last modified 21.11.2024 05:11:16
A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be ...
CVE-2020-1735
- EPSS 0.14%
- Published 16.03.2020 16:15:13
- Last modified 21.11.2024 05:11:16
A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believ...
CVE-2020-1739
- EPSS 0.04%
- Published 12.03.2020 18:15:12
- Last modified 21.11.2024 05:11:16
A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could ta...
- EPSS 0.04%
- Published 11.03.2020 19:15:13
- Last modified 21.11.2024 05:11:16
A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in ...
CVE-2014-4658
- EPSS 0.12%
- Published 20.02.2020 15:15:11
- Last modified 21.11.2024 02:10:39
The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtain sensitive key information by reading a file.
CVE-2014-4659
- EPSS 0.08%
- Published 20.02.2020 15:15:11
- Last modified 21.11.2024 02:10:39
Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.
CVE-2014-4657
- EPSS 2.24%
- Published 20.02.2020 15:15:11
- Last modified 21.11.2024 02:10:39
The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.
CVE-2014-4678
- EPSS 4.73%
- Published 20.02.2020 03:15:10
- Last modified 21.11.2024 02:10:41
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-465...
CVE-2014-4660
- EPSS 0.12%
- Published 20.02.2020 03:15:10
- Last modified 21.11.2024 02:10:39
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence o...
CVE-2014-4967
- EPSS 4.75%
- Published 18.02.2020 15:15:11
- Last modified 21.11.2024 02:11:11
Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansible managed host and providing a crafted fact, as demonstrated by a fact with (1) a trailing " src=" c...