CVE-2021-3620
- EPSS 0.2%
- Veröffentlicht 03.03.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:00
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
CVE-2021-3583
- EPSS 0.3%
- Veröffentlicht 22.09.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:54
A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not r...
CVE-2020-10729
- EPSS 0.09%
- Veröffentlicht 27.05.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 04:55:56
A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as the template caching action for the same file since no re-evaluation happens. The highest threat from t...
CVE-2021-20228
- EPSS 0.14%
- Veröffentlicht 29.04.2021 16:15:09
- Zuletzt bearbeitet 21.11.2024 05:46:10
A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive informa...
CVE-2020-14365
- EPSS 0.07%
- Veröffentlicht 23.09.2020 13:15:15
- Zuletzt bearbeitet 21.11.2024 05:03:06
A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to ...
CVE-2020-14332
- EPSS 0.14%
- Veröffentlicht 11.09.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:03:01
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threa...
CVE-2020-14330
- EPSS 0.12%
- Veröffentlicht 11.09.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:03:01
An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed tasks to read keys use...
- EPSS 0.06%
- Veröffentlicht 12.05.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:17
A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when the ldap_attr and ldap_e...
CVE-2020-10685
- EPSS 0.14%
- Veröffentlicht 11.05.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:51
A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when using modules which decrypts...
CVE-2020-10691
- EPSS 0.1%
- Veröffentlicht 30.04.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:51
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker ...