Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

49 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (3.1)0.11%—Redhat Ansible Automation Platform11/7/202517/6/2026
A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to read transmitted data.
AplazadaAlta (8.8)0.58%—Redhat Ansible Automation PlatformAI30/6/202517/6/2026
A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 templates. This vulnerability allows authenticated users to inject expressions that execute commands or access sensitive files on the EDA worker. In OpenShift, it can lead…
AplazadaAlta (8.8)0.61%—Redhat Ansible Automation PlatformAIRedhat EDAAI30/6/202517/6/2026
A flaw was found in Ansible Automation Platform’s EDA component where user-supplied Git URLs are passed unsanitized to the git ls-remote command. This vulnerability allows an authenticated attacker to inject arguments and execute arbitrary commands on the EDA worker. In Kubernetes/OpenShift environments, this can lead…
AplazadaMedia (6.5)0.41%—Redhat Ansible Automation PlatformAIRedhat Event Driven AnsibleAIRedhat Event StreamsAI28/3/202517/6/2026
A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any "debug" action in a rulebook and also affects Event Streams.
ModificadaMedia (6.1)0.40%—Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside16/10/202417/6/2026
A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL, which can lead to redirecting, injecting malicious script, stealing sessions and data.
AplazadaMedia (5.3)0.16%—Redhat Ansible Automation PlatformAIRedhat Event Driven AutomationAI8/10/202417/6/2026
A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensitive information. An attacker with network access could exploit this vulnerability by sniffing the plaintext data transmitted between the EDA and AAP. An attacker with system access could exploit this…
ModificadaMedia (5.5)0.30%—Redhat AnsibleRedhat Enterprise LinuxRedhat Ansible Automation PlatformRedhat Ansible Developer+26/2/202417/6/2026
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
ModificadaAlta (7.5)1.1%—Redhat Ansible Automation PlatformRedhat Enterprise LinuxRedhat Update InfrastructureCryptography.io Cryptography+15/2/202417/6/2026
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
ModificadaMedia (6.3)1.0%—Redhat Ansible Automation PlatformRedhat Ansible InsideRedhat Ansible DeveloperDebian Linux18/12/202317/6/2026
An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.
ModificadaAlta (7.8)0.54%—Redhat AnsibleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Ansible Automation Platform+212/12/202317/6/2026
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
ModificadaMedia (6.5)0.98%—Redhat Ansible Automation PlatformRedhat Satellite14/11/202317/6/2026
A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy importer of Ansible Automation Hub, a symlink could be dropped on the disk, resulting in files being overwritten.
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaMedia (6.3)0.64%—Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside4/10/202317/6/2026
A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the loss of confidentiality, integrity, and availability.
ModificadaAlta (7.8)0.25%—Redhat Ansible Automation PlatformRedhat Ansible Collection4/10/202317/6/2026
A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality, integrity, and availability.
ModificadaMedia (5.4)0.81%💥 PoCRedhat Ansible Automation ControllerRedhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside4/10/202317/6/2026
An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.
ModificadaMedia (5.5)0.29%—Pulpproject Pulp AnsibleRedhat Ansible Automation PlatformRedhat SatelliteRedhat Update Infrastructure25/10/202217/6/2026
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
ModificadaMedia (6.1)0.51%—Redhat Ansible Automation Platform13/9/202217/6/2026
Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection
ModificadaMedia (6.5)0.41%—Redhat Ansible Automation PlatformRedhat Openshift Container PlatformFedoraproject Fedora1/9/202217/6/2026
An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting in a loss of confidentiality.
ModificadaAlta (8.8)0.24%—Redhat Ansible Automation Platform Early AccessRedhat Ansible Automation Platform Text-only AdvisoriesRedhat Ansible TowerRedhat Ansible Automation Platform25/8/202217/6/2026
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.
ModificadaMedia (6.5)0.87%—Redhat Ansible Automation Platform18/8/202217/6/2026
A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remove the superuser privileges.
ModificadaMedia (5.5)0.25%—Redhat Ansible Automation PlatformRedhat Ansible Galaxy18/4/202217/6/2026
A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly excluded via the ``build_ignore`` list in "galaxy.yml" include files in the ``.tar.gz`` file. This contains sensitive info, such as the user's Ansible Galaxy API key and…
ModificadaMedia (5.5)0.39%—Redhat Ansible Automation Platform Early AccessRedhat Ansible EngineRedhat OpenstackRedhat Virtualization+53/3/202217/6/2026
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
ModificadaAlta (7.1)0.90%—Redhat Ansible Automation PlatformRedhat Ansible EngineRedhat Ansible Tower22/9/202117/6/2026
A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows…
ModificadaAlta (7.5)2.1%—Redhat Ansible EngineRedhat Ansible Automation PlatformRedhat Ansible TowerDebian Linux29/4/202117/6/2026
A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to…
Orbitaley — Vulnerabilidades