Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
67 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 0.47% | — | Redhat AnsibleRedhat Ansible TowerRedhat Cloudforms Management EngineRedhat Openstack+2 | 16/3/2020 | 17/6/2026 | A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable. | |
| Modificada | Media (5.5) | 0.51% | — | Redhat Ansible EngineRedhat Ansible TowerDebian LinuxFedoraproject Fedora | 16/3/2020 | 17/6/2026 | A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2.9.x versions prior to 2.9.7, when managing kubernetes using the k8s module. Sensitive parameters such as passwords and tokens are passed to kubectl from the command… | |
| Modificada | Baja (3.9) | 0.36% | — | Redhat AnsibleRedhat Ansible TowerRedhat Cloudforms Management EngineRedhat Openstack+2 | 12/3/2020 | 17/6/2026 | A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on… | |
| Modificada | Media (5) | 0.40% | — | Redhat AnsibleRedhat Ansible TowerRedhat Cloudforms Management EngineRedhat Openstack+2 | 11/3/2020 | 17/6/2026 | A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with "umask 77 && mkdir -p… | |
| Modificada | Alta (7.8) | 0.36% | — | Redhat Ansible EngineRedhat Ansible Tower | 9/3/2020 | 17/6/2026 | A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file… | |
| Modificada | Alta (7.4) | 0.46% | — | Redhat Ansible EngineRedhat Ansible Tower | 3/3/2020 | 17/6/2026 | A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could take advantage and run arbitrary commands by overwriting the ansible… | |
| Modificada | Media (6.5) | 1.9% | — | Redhat AnsibleRedhat Ansible TowerRedhat Ceph StorageRedhat Cloudforms Management Engine+4 | 2/1/2020 | 17/6/2026 | Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data. | |
| Modificada | Media (5.3) | 1.1% | — | Redhat Ansible Tower | 19/12/2019 | 17/6/2026 | A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and the password contains the '#' character. This request would cause a socket error in RabbitMQ when parsing the password and an HTTP error code 500 and partial password disclose will occur in… | |
| Modificada | Media (5.5) | 0.31% | — | Redhat Ansible Tower | 19/12/2019 | 17/6/2026 | A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readable. These files include both the SECRET_KEY and the database backup. Any user with access to the Tower server, and knowledge of when a backup is run, could retrieve every credential stored in Tower.… | |
| Modificada | Alta (8.2) | 1.5% | — | Redhat Ansible TowerRedhat Enterprise Linux | 19/12/2019 | 17/6/2026 | A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If the default admin user is still active, an attacker could guess the password… | |
| Modificada | Alta (8.4) | 0.24% | — | Redhat Ansible Tower | 26/11/2019 | 17/6/2026 | A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license. | |
| Modificada | Media (5.5) | 0.42% | — | Redhat Ansible EngineRedhat Ansible Tower | 14/10/2019 | 17/6/2026 | A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result,… | |
| Modificada | Media (4.3) | 1.3% | — | Jenkins Ansible Tower | 30/4/2019 | 17/6/2026 | A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doFillTowerCredentialsIdItems method allowed attackers with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins. | |
| Modificada | Alta (8.8) | 1.8% | — | Jenkins Ansible Tower | 30/4/2019 | 17/6/2026 | A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through… | |
| Modificada | Alta (8.8) | 1.5% | — | Jenkins Ansible Tower | 30/4/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through… | |
| Modificada | Alta (7.2) | 1.3% | — | Redhat Ansible Tower | 28/3/2019 | 17/6/2026 | When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges. | |
| Modificada | Media (5.5) | 2.5% | — | Artifex GhostscriptRedhat Ansible TowerRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+8 | 25/3/2019 | 17/6/2026 | It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. | |
| Modificada | Media (5.5) | 2.5% | — | Artifex GhostscriptRedhat Ansible TowerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+7 | 25/3/2019 | 17/6/2026 | It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. | |
| Modificada | Crítica (9.8) | 1.1% | — | Redhat Ansible Tower | 3/1/2019 | 17/6/2026 | Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory… | |
| Modificada | Alta (7.8) | 0.36% | — | Redhat Ansible EngineRedhat Ansible TowerDebian LinuxSuse Package HUB | 23/10/2018 | 17/6/2026 | Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list. | |
| Modificada | Alta (8.8) | 4.4% | — | ParamikoRedhat Ansible TowerRedhat Virtualization HostRedhat Enterprise Linux Desktop+7 | 8/10/2018 | 17/6/2026 | Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity. | |
| Modificada | Crítica (9.8) | 97% | 💥 Exploit | Git-scm GITRedhat Ansible TowerRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+7 | 6/10/2018 | 17/6/2026 | Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a '-' character. | |
| Modificada | Alta (8) | 0.64% | — | Redhat Ansible Tower | 11/9/2018 | 17/6/2026 | A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level access to the database. | |
| Modificada | Media (6.5) | 0.60% | — | Redhat Ansible TowerRedhat Cloudforms Management Engine | 22/8/2018 | 17/6/2026 | Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that X-Forwarded-For header allows internal servers to deploy other systems (using callback). | |
| Modificada | Alta (8.8) | 0.90% | — | Redhat Ansible Tower | 22/8/2018 | 17/6/2026 | Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could exploit this by tricking already authenticated users into visiting a malicious site and hijacking the authtoken cookie. |