Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
223 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.30% | — | Redhat AnsibleRedhat Enterprise LinuxRedhat Ansible Automation PlatformRedhat Ansible Developer+2 | 6/2/2024 | 17/6/2026 | An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values. | |
| Modificada | Alta (7.5) | 1.1% | — | Redhat Ansible Automation PlatformRedhat Enterprise LinuxRedhat Update InfrastructureCryptography.io Cryptography+1 | 5/2/2024 | 17/6/2026 | A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. | |
| Modificada | Media (6.3) | 1.0% | — | Redhat Ansible Automation PlatformRedhat Ansible InsideRedhat Ansible DeveloperDebian Linux | 18/12/2023 | 17/6/2026 | An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path. | |
| Modificada | Alta (7.8) | 0.54% | — | Redhat AnsibleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Ansible Automation Platform+2 | 12/12/2023 | 17/6/2026 | A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data. | |
| Modificada | Media (6.5) | 0.98% | — | Redhat Ansible Automation PlatformRedhat Satellite | 14/11/2023 | 17/6/2026 | A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy importer of Ansible Automation Hub, a symlink could be dropped on the disk, resulting in files being overwritten. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (6.3) | 0.64% | — | Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside | 4/10/2023 | 17/6/2026 | A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the loss of confidentiality, integrity, and availability. | |
| Modificada | Alta (7.8) | 0.25% | — | Redhat Ansible Automation PlatformRedhat Ansible Collection | 4/10/2023 | 17/6/2026 | A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality, integrity, and availability. | |
| Modificada | Media (5.4) | 0.81% | 💥 PoC | Redhat Ansible Automation ControllerRedhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside | 4/10/2023 | 17/6/2026 | An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise. | |
| Modificada | Alta (8.8) | 1.7% | — | Ansible-semaphore Ansible Semaphore | 28/8/2023 | 17/6/2026 | An issue in ansible semaphore v.2.8.90 allows a remote attacker to execute arbitrary code via a crafted payload to the extra variables parameter. | |
| Modificada | Media (5.3) | 0.38% | — | Jenkins Ansible | 16/5/2023 | 17/6/2026 | Jenkins Ansible Plugin 204.v8191fd551eb_f and earlier does not mask extra variables displayed on the configuration form, increasing the potential for attackers to observe and capture them. | |
| Modificada | Media (4.3) | 0.38% | — | Jenkins Ansible | 16/5/2023 | 17/6/2026 | Jenkins Ansible Plugin 204.v8191fd551eb_f and earlier stores extra variables unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. | |
| Modificada | Media (5.5) | 0.20% | — | Openstack Tripleo AnsibleRedhat OpenstackRedhat Openstack FOR IBM Power | 23/3/2023 | 17/6/2026 | A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important… | |
| Modificada | Media (5.5) | 0.20% | — | Openstack Tripleo AnsibleRedhat OpenstackRedhat Openstack FOR IBM Power | 23/3/2023 | 17/6/2026 | A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important configuration… | |
| Modificada | Crítica (9.8) | 0.87% | — | Ansible-semaphore Ansible Semaphore | 18/3/2023 | 17/6/2026 | api/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication. | |
| Modificada | Media (4.3) | 0.40% | — | Ansible-ntp Project Ansible-ntp | 2/1/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in drybjed ansible-ntp. Affected by this issue is some unknown functionality of the file meta/main.yml. The manipulation leads to insufficient control of network message volume. The attack can only be done within the local network. The complexity of… | |
| Modificada | Alta (7.5) | 0.78% | — | Redhat AnsibleRedhat Ansible Collection | 28/10/2022 | 17/6/2026 | A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs. | |
| Modificada | Media (5.5) | 0.29% | — | Pulpproject Pulp AnsibleRedhat Ansible Automation PlatformRedhat SatelliteRedhat Update Infrastructure | 25/10/2022 | 17/6/2026 | The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only. | |
| Modificada | Media (6.1) | 0.51% | — | Redhat Ansible Automation Platform | 13/9/2022 | 17/6/2026 | Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection | |
| Modificada | Media (6.5) | 0.41% | — | Redhat Ansible Automation PlatformRedhat Openshift Container PlatformFedoraproject Fedora | 1/9/2022 | 17/6/2026 | An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting in a loss of confidentiality. | |
| Modificada | Alta (8.8) | 0.24% | — | Redhat Ansible Automation Platform Early AccessRedhat Ansible Automation Platform Text-only AdvisoriesRedhat Ansible TowerRedhat Ansible Automation Platform | 25/8/2022 | 17/6/2026 | A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment. | |
| Modificada | Alta (7.8) | 0.33% | — | Redhat Ansible Runner | 24/8/2022 | 17/6/2026 | A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters getting executed as host's shell command. A developer could unintentionally write code that gets executed in the host rather than the virtual environment. | |
| Modificada | Media (6.3) | 0.20% | — | Redhat Ansible Runner | 23/8/2022 | 17/6/2026 | A race condition flaw was found in ansible-runner, where an attacker could watch for rapid creation and deletion of a temporary directory, substitute their directory at that name, and then have access to ansible-runner's private_data_dir the next time ansible-runner made use of the private_data_dir. The highest Threat… | |
| Modificada | Media (6.6) | 0.29% | — | Redhat Ansible Runner | 23/8/2022 | 17/6/2026 | A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world R/W locations. This flaw allows an attacker to pre-create the directory, resulting in reading private information or forcing ansible-runner to write files as the legitimate user in a place they did… | |
| Modificada | Media (6.5) | 0.87% | — | Redhat Ansible Automation Platform | 18/8/2022 | 17/6/2026 | A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remove the superuser privileges. |