CVE-2024-11079
- EPSS 0.39%
- Veröffentlicht 12.11.2024 00:15:15
- Zuletzt bearbeitet 18.12.2024 04:15:06
A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module ...
CVE-2024-9902
- EPSS 0.05%
- Veröffentlicht 06.11.2024 10:15:06
- Zuletzt bearbeitet 25.02.2025 20:15:36
A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against th...
CVE-2024-9620
- EPSS 0.03%
- Veröffentlicht 08.10.2024 17:15:57
- Zuletzt bearbeitet 10.10.2024 12:56:30
A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensitive information. An attacker with network access could exploit this vulnerability by sniffing the plaintext data transmitted betwe...
CVE-2024-8775
- EPSS 0.03%
- Veröffentlicht 14.09.2024 03:15:08
- Zuletzt bearbeitet 10.02.2025 19:15:39
A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_...
CVE-2024-6840
- EPSS 0.14%
- Veröffentlicht 12.09.2024 17:15:05
- Zuletzt bearbeitet 12.09.2024 18:14:03
An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S API server to send an HTTP request with a service account token mounted via `automountServiceAccountToken: true`, resulting in priv...
CVE-2024-1657
- EPSS 0.08%
- Veröffentlicht 25.04.2024 17:15:48
- Zuletzt bearbeitet 21.11.2024 08:51:01
A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rulebook data f...
CVE-2016-9587
- EPSS 3.99%
- Veröffentlicht 24.04.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:26
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to th...