CVE-2024-0690
- EPSS 0.3%
- Veröffentlicht 06.02.2024 12:15:55
- Zuletzt bearbeitet 04.11.2025 19:16:27
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this iss...
CVE-2023-5764
- EPSS 0.54%
- Veröffentlicht 12.12.2023 22:15:22
- Zuletzt bearbeitet 21.11.2024 08:42:26
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating i...
CVE-2022-3697
- EPSS 0.73%
- Veröffentlicht 28.10.2022 16:15:16
- Zuletzt bearbeitet 21.11.2024 07:20:03
A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely,...
CVE-2021-20180
- EPSS 0.31%
- Veröffentlicht 16.03.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 05:46:04
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline cre...
CVE-2021-20191
- EPSS 0.35%
- Veröffentlicht 26.05.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 05:46:06
A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The ...
CVE-2021-20178
- EPSS 0.34%
- Veröffentlicht 26.05.2021 12:15:18
- Zuletzt bearbeitet 21.11.2024 05:46:04
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline cre...
CVE-2021-3447
- EPSS 0.33%
- Veröffentlicht 01.04.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:32
A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nodes, as well as being made visible on the controller node when run in verbose mode. These parameters w...
CVE-2020-25635
- EPSS 0.32%
- Veröffentlicht 05.10.2020 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:18:17
A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed. Files would remain in the bucket exposing the data. This issue affects directly data confidentiality.
CVE-2020-25636
- EPSS 0.3%
- Veröffentlicht 05.10.2020 13:15:13
- Zuletzt bearbeitet 21.11.2024 05:18:18
A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are written directly to the root bucket, making possible to have collisions when running multiple ansible processe...
CVE-2019-14904
- EPSS 0.42%
- Veröffentlicht 26.08.2020 03:15:11
- Zuletzt bearbeitet 21.11.2024 04:27:39
A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the remote machine. An attacker coul...