CVE-2019-14905
- EPSS 0.05%
- Published 31.03.2020 17:15:26
- Last modified 21.11.2024 04:27:39
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code c...
CVE-2020-1753
- EPSS 0.04%
- Published 16.03.2020 15:15:13
- Last modified 21.11.2024 05:11:18
A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2.9.x versions prior to 2.9.7, when managing kubernetes using the k8s module. Sensitive parameters suc...
CVE-2020-1737
- EPSS 0.12%
- Published 09.03.2020 16:15:12
- Last modified 21.11.2024 05:11:16
A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take...
CVE-2020-1734
- EPSS 0.13%
- Published 03.03.2020 22:15:10
- Last modified 21.11.2024 05:11:16
A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could...
CVE-2019-14858
- EPSS 0.05%
- Published 14.10.2019 15:15:09
- Last modified 21.11.2024 04:27:30
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the...
CVE-2019-14846
- EPSS 0.14%
- Published 08.10.2019 19:15:10
- Last modified 21.11.2024 04:27:29
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBU...
CVE-2018-16876
- EPSS 1.03%
- Published 03.01.2019 15:29:01
- Last modified 21.11.2024 03:53:30
ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.
CVE-2018-16859
- EPSS 0.1%
- Published 29.11.2018 18:29:00
- Last modified 21.11.2024 03:53:27
Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can vie...
CVE-2018-16837
- EPSS 0.04%
- Published 23.10.2018 15:29:00
- Last modified 21.11.2024 03:53:24
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear te...
CVE-2016-8647
- EPSS 0.17%
- Published 26.07.2018 14:29:00
- Last modified 21.11.2024 02:59:45
An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed.