CVE-2019-10156
- EPSS 1.77%
- Veröffentlicht 30.07.2019 23:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:32
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable su...
CVE-2019-3828
- EPSS 0.53%
- Veröffentlicht 27.03.2019 13:29:01
- Zuletzt bearbeitet 21.11.2024 04:42:37
Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.
CVE-2018-16876
- EPSS 2.48%
- Veröffentlicht 03.01.2019 15:29:01
- Zuletzt bearbeitet 21.11.2024 03:53:30
ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.
CVE-2016-8614
- EPSS 2.46%
- Veröffentlicht 31.07.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 02:59:40
A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.
CVE-2016-8628
- EPSS 3.25%
- Veröffentlicht 31.07.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 02:59:42
Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the user Ansibl...
CVE-2017-7466
- EPSS 3.18%
- Veröffentlicht 22.06.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:31:57
Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a client system being managed by Ansible, and the ability to send facts back to the Ansible server, could...
CVE-2013-2233
- EPSS 1.96%
- Veröffentlicht 04.05.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 01:51:17
Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys.
CVE-2016-9587
- EPSS 17.79%
- Veröffentlicht 24.04.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:26
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to th...
CVE-2017-7550
- EPSS 3.56%
- Veröffentlicht 21.11.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fix...
CVE-2014-3498
- EPSS 2.52%
- Veröffentlicht 08.06.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands.