CVE-2018-16879
- EPSS 0.23%
- Published 03.01.2019 14:29:00
- Last modified 21.11.2024 03:53:30
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as...
CVE-2018-16837
- EPSS 0.04%
- Published 23.10.2018 15:29:00
- Last modified 21.11.2024 03:53:24
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear te...
CVE-2018-1000805
- EPSS 0.42%
- Published 08.10.2018 15:29:00
- Last modified 21.11.2024 03:40:23
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
CVE-2018-17456
- EPSS 70.7%
- Published 06.10.2018 14:29:00
- Last modified 21.11.2024 03:54:27
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has ...
- EPSS 0.09%
- Published 11.09.2018 13:29:00
- Last modified 21.11.2024 02:57:23
A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level access to the ...
CVE-2017-7528
- EPSS 0.16%
- Published 22.08.2018 16:29:03
- Last modified 21.11.2024 03:32:05
Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that X-Forwarded-For header allows internal servers to deploy other systems (using callback).
CVE-2018-10884
- EPSS 0.18%
- Published 22.08.2018 14:29:00
- Last modified 21.11.2024 03:42:13
Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could exploit this by tricking already authenticated users into visiting a malicious site and hijacking the aut...
CVE-2015-9262
- EPSS 2.37%
- Published 01.08.2018 23:29:00
- Last modified 21.11.2024 02:40:11
_XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow.
CVE-2018-14682
- EPSS 1.34%
- Published 28.07.2018 23:29:00
- Last modified 21.11.2024 03:49:34
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.
CVE-2018-14681
- EPSS 1.34%
- Published 28.07.2018 23:29:00
- Last modified 21.11.2024 03:49:34
An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.