CVE-2020-1734
- EPSS 0.13%
- Published 03.03.2020 22:15:10
- Last modified 21.11.2024 05:11:16
A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could...
CVE-2019-14864
- EPSS 0.94%
- Published 02.01.2020 15:15:12
- Last modified 21.11.2024 04:27:31
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This woul...
CVE-2019-19342
- EPSS 0.2%
- Published 19.12.2019 21:15:14
- Last modified 21.11.2024 04:34:36
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and the password contains the '#' character. This request would cause a socket error in RabbitMQ when parsing the password and an HTTP...
CVE-2019-19341
- EPSS 0.04%
- Published 19.12.2019 21:15:14
- Last modified 21.11.2024 04:34:36
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readable. These files include both the SECRET_KEY and the database backup. Any user with access to the Tower server, and knowledge of wh...
CVE-2019-19340
- EPSS 0.41%
- Published 19.12.2019 21:15:13
- Last modified 21.11.2024 04:34:36
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If the defaul...
CVE-2019-14890
- EPSS 0.02%
- Published 26.11.2019 07:15:11
- Last modified 21.11.2024 04:27:37
A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Towe...
CVE-2019-14858
- EPSS 0.05%
- Published 14.10.2019 15:15:09
- Last modified 21.11.2024 04:27:30
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the...
CVE-2019-3869
- EPSS 0.33%
- Published 28.03.2019 14:29:00
- Last modified 21.11.2024 04:42:45
When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.
CVE-2019-3838
- EPSS 1.41%
- Published 25.03.2019 19:29:01
- Last modified 21.11.2024 04:42:40
It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the cons...
CVE-2019-3835
- EPSS 1.7%
- Published 25.03.2019 19:29:01
- Last modified 21.11.2024 04:42:39
It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains i...