Redhat

Ansible

55 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.43%
  • Veröffentlicht 20.02.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 02:10:39

The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.

  • EPSS 5.24%
  • Veröffentlicht 20.02.2020 03:15:10
  • Zuletzt bearbeitet 21.11.2024 02:10:41

The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-465...

  • EPSS 0.38%
  • Veröffentlicht 20.02.2020 03:15:10
  • Zuletzt bearbeitet 21.11.2024 02:10:39

Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence o...

  • EPSS 3.55%
  • Veröffentlicht 18.02.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 02:11:11

Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansible managed host and providing a crafted fact, as demonstrated by a fact with (1) a trailing " src=" c...

  • EPSS 3.55%
  • Veröffentlicht 18.02.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 02:11:11

Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which allows remote attackers to execute arbitrary code via (1) crafted lookup('pipe') calls or (2) crafted...

  • EPSS 1.19%
  • Veröffentlicht 09.01.2020 13:15:10
  • Zuletzt bearbeitet 21.11.2024 02:06:47

Ansible prior to 1.5.4 mishandles the evaluation of some strings.

Exploit
  • EPSS 1.87%
  • Veröffentlicht 02.01.2020 15:15:12
  • Zuletzt bearbeitet 21.11.2024 04:27:31

Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This woul...

  • EPSS 1.66%
  • Veröffentlicht 26.11.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 04:27:30

ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None

Exploit
  • EPSS 1.87%
  • Veröffentlicht 25.11.2019 16:15:13
  • Zuletzt bearbeitet 21.11.2024 04:18:40

A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for all gcp modules is ...

  • EPSS 1.52%
  • Veröffentlicht 22.11.2019 13:15:11
  • Zuletzt bearbeitet 21.11.2024 04:18:39

ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped t...