CVE-2018-16879
- EPSS 0.23%
- Veröffentlicht 03.01.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:30
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as...
CVE-2018-16837
- EPSS 0.04%
- Veröffentlicht 23.10.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:24
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear te...
CVE-2018-1000805
- EPSS 0.42%
- Veröffentlicht 08.10.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:23
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
CVE-2018-17456
- EPSS 70.7%
- Veröffentlicht 06.10.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:27
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has ...
- EPSS 0.09%
- Veröffentlicht 11.09.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 02:57:23
A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level access to the ...
CVE-2017-7528
- EPSS 0.16%
- Veröffentlicht 22.08.2018 16:29:03
- Zuletzt bearbeitet 21.11.2024 03:32:05
Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that X-Forwarded-For header allows internal servers to deploy other systems (using callback).
CVE-2018-10884
- EPSS 0.18%
- Veröffentlicht 22.08.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:13
Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could exploit this by tricking already authenticated users into visiting a malicious site and hijacking the aut...
CVE-2015-9262
- EPSS 2.37%
- Veröffentlicht 01.08.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 02:40:11
_XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow.
CVE-2018-14682
- EPSS 1.34%
- Veröffentlicht 28.07.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:34
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.
CVE-2018-14681
- EPSS 1.34%
- Veröffentlicht 28.07.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:34
An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.