CVE-2024-9902
- EPSS 0.05%
- Published 06.11.2024 10:15:06
- Last modified 25.02.2025 20:15:36
A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against th...
CVE-2024-10033
- EPSS 0.07%
- Published 16.10.2024 17:15:13
- Last modified 26.03.2025 05:15:39
A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL, which can lead to redirecting...
CVE-2024-9620
- EPSS 0.03%
- Published 08.10.2024 17:15:57
- Last modified 10.10.2024 12:56:30
A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensitive information. An attacker with network access could exploit this vulnerability by sniffing the plaintext data transmitted betwe...
CVE-2024-8775
- EPSS 0.03%
- Published 14.09.2024 03:15:08
- Last modified 10.02.2025 19:15:39
A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_...
CVE-2024-1657
- EPSS 0.08%
- Published 25.04.2024 17:15:48
- Last modified 21.11.2024 08:51:01
A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rulebook data f...
CVE-2024-1394
- EPSS 1.02%
- Published 21.03.2024 13:00:08
- Last modified 13.05.2025 09:15:19
A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. Th...
CVE-2024-0690
- EPSS 0.06%
- Published 06.02.2024 12:15:55
- Last modified 17.01.2025 20:15:27
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this iss...
CVE-2023-50782
- EPSS 0.71%
- Published 05.02.2024 21:15:11
- Last modified 21.11.2024 08:37:18
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
CVE-2023-5115
- EPSS 0.34%
- Published 18.12.2023 14:15:10
- Last modified 06.12.2024 11:15:07
An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path...
CVE-2023-5764
- EPSS 0.07%
- Published 12.12.2023 22:15:22
- Last modified 21.11.2024 08:42:26
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating i...