CVE-2021-20228
- EPSS 0.14%
- Veröffentlicht 29.04.2021 16:15:09
- Zuletzt bearbeitet 21.11.2024 05:46:10
A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive informa...
CVE-2021-3447
- EPSS 0.06%
- Veröffentlicht 01.04.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:32
A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nodes, as well as being made visible on the controller node when run in verbose mode. These parameters w...
CVE-2021-20253
- EPSS 0.28%
- Veröffentlicht 09.03.2021 18:15:15
- Zuletzt bearbeitet 21.11.2024 05:46:13
A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the privilege from a low privileged user to the awx user from outside the isolated environment. The highest threat from ...
CVE-2020-14365
- EPSS 0.07%
- Veröffentlicht 23.09.2020 13:15:15
- Zuletzt bearbeitet 21.11.2024 05:03:06
A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to ...
CVE-2020-14337
- EPSS 0.88%
- Veröffentlicht 31.07.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:03:02
A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, remote attacker to retrieve pages from the default organization and verify existing usernames. The highe...
CVE-2020-10782
- EPSS 0.04%
- Veröffentlicht 18.06.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 04:56:03
An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable and exposed from the rsyslog configuration file, which has set the wrong world-readable permissions. ...
- EPSS 0.04%
- Veröffentlicht 15.05.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:58
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE file...
- EPSS 0.06%
- Veröffentlicht 12.05.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:17
A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when the ldap_attr and ldap_e...
CVE-2020-10685
- EPSS 0.14%
- Veröffentlicht 11.05.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:51
A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when using modules which decrypts...
CVE-2020-10691
- EPSS 0.1%
- Veröffentlicht 30.04.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:51
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker ...