Search CVE reports


Toggle filters

31 – 40 of 83 results


CVE-2020-14330

Medium priority
Vulnerable

An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2019-14904

Low priority

Some fixes available 2 of 4

A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the remote...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Not affected Fixed
Show less packages

CVE-2020-10744

Low priority

Some fixes available 3 of 6

An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-1746

Medium priority
Needs evaluation

A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when the...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-10685

Medium priority
Vulnerable

A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when using...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2020-10691

Medium priority
Vulnerable

An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Vulnerable Not affected
Show less packages

CVE-2019-14905

Medium priority
Vulnerable

A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2020-10684

Medium priority
Vulnerable

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2020-1740

Medium priority
Vulnerable

A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a temporary...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2020-1738

Medium priority
Needs evaluation

A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages