CVE-2021-4112
- EPSS 0.05%
- Published 25.08.2022 20:15:09
- Last modified 21.11.2024 06:36:55
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.
CVE-2021-3583
- EPSS 0.3%
- Published 22.09.2021 12:15:07
- Last modified 21.11.2024 06:21:54
A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not r...
CVE-2020-14329
- EPSS 0.04%
- Published 27.05.2021 20:15:07
- Last modified 21.11.2024 05:03:01
A data exposure flaw was found in Ansible Tower in versions before 3.7.2, where sensitive data can be exposed from the /api/v2/labels/ endpoint. This flaw allows users from other organizations in the system to retrieve any label from the organization...
CVE-2020-14328
- EPSS 0.04%
- Published 27.05.2021 20:15:07
- Last modified 21.11.2024 05:03:01
A flaw was found in Ansible Tower in versions before 3.7.2. A Server Side Request Forgery flaw can be abused by supplying a URL which could lead to the server processing it connecting to internal services or exposing additional internal services and ...
CVE-2020-14327
- EPSS 0.04%
- Published 27.05.2021 20:15:07
- Last modified 21.11.2024 05:03:01
A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower server is abused by supplying a URL that could lead to the server processing it. This flaw leads to the connect...
CVE-2020-10709
- EPSS 0.09%
- Published 27.05.2021 19:15:07
- Last modified 21.11.2024 04:55:53
A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authentication. This flaw allows an attacker to obtain a refresh token that does not expire. The original t...
CVE-2020-10698
- EPSS 0.04%
- Published 27.05.2021 19:15:07
- Last modified 21.11.2024 04:55:52
A flaw was found in Ansible Tower when running jobs. This flaw allows an attacker to access the stdout of the executed jobs which are run from other organizations. Some sensible data can be disclosed. However, critical data should not be disclosed, a...
CVE-2020-10697
- EPSS 0.13%
- Published 27.05.2021 19:15:07
- Last modified 21.11.2024 04:55:52
A flaw was found in Ansible Tower when running Openshift. Tower runs a memcached, which is accessed via TCP. An attacker can take advantage of writing a playbook polluting this cache, causing a denial of service attack. This attack would not complete...
CVE-2021-20191
- EPSS 0.03%
- Published 26.05.2021 21:15:08
- Last modified 21.11.2024 05:46:06
A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The ...
CVE-2021-20178
- EPSS 0.03%
- Published 26.05.2021 12:15:18
- Last modified 21.11.2024 05:46:04
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline cre...