Search CVE reports


Toggle filters

41 – 50 of 83 results


CVE-2020-1736

Medium priority
Needs evaluation

A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-1735

Medium priority
Needs evaluation

A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-1753

Medium priority
Needs evaluation

A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2.9.x versions prior to 2.9.7, when managing kubernetes using the k8s module....

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-1739

Medium priority

Some fixes available 4 of 5

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node....

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-1733

Medium priority

Some fixes available 3 of 4

A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-1737

Medium priority
Needs evaluation

A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-1734

Medium priority
Needs evaluation

A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2014-4659

Medium priority
Ignored

Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected
Show less packages

CVE-2014-4658

Medium priority

Some fixes available 1 of 2

The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtain sensitive key information by reading a file.

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Not affected
Show less packages

CVE-2014-4657

Medium priority
Ignored

The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected
Show less packages