Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
223 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.25% | — | Redhat Ansible Automation PlatformRedhat Ansible Galaxy | 18/4/2022 | 17/6/2026 | A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly excluded via the ``build_ignore`` list in "galaxy.yml" include files in the ``.tar.gz`` file. This contains sensitive info, such as the user's Ansible Galaxy API key and… | |
| Modificada | Alta (8) | 1.0% | — | Theforeman Foreman AnsibleRedhat Satellite | 23/3/2022 | 17/6/2026 | An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | |
| Modificada | Media (5.5) | 0.31% | — | Redhat Ansible | 16/3/2022 | 17/6/2026 | A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to… | |
| Modificada | Media (5.5) | 0.39% | — | Redhat Ansible Automation Platform Early AccessRedhat Ansible EngineRedhat OpenstackRedhat Virtualization+5 | 3/3/2022 | 17/6/2026 | A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality. | |
| Modificada | Crítica (9.8) | 1.6% | — | Confluent Ansible | 29/9/2021 | 17/6/2026 | Confluent Ansible (cp-ansible) version 5.5.0, 5.5.1, 5.5.2 and 6.0.0 is vulnerable to Incorrect Access Control via its auxiliary component that allows remote attackers to access sensitive information. | |
| Modificada | Media (5.5) | 0.30% | — | Confluent Cp-ansible | 29/9/2021 | 17/6/2026 | Insecure permissions in Confluent Ansible (cp-ansible) 5.5.0, 5.5.1, 5.5.2 and 6.0.0 allows local attackers to access some sensitive information (private keys, state database). | |
| Modificada | Alta (7.1) | 0.90% | — | Redhat Ansible Automation PlatformRedhat Ansible EngineRedhat Ansible Tower | 22/9/2021 | 17/6/2026 | A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows… | |
| Modificada | Alta (8.8) | 1.3% | — | Ceph-ansible | 28/5/2021 | 17/6/2026 | A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services. Any authenticated attacker can abuse this flaw to brute-force Ceph deployments, and gain administrator access to Ceph clusters via the Ceph dashboard to initiate… | |
| Modificada | Baja (3.3) | 0.27% | — | Redhat Ansible Tower | 27/5/2021 | 17/6/2026 | A data exposure flaw was found in Ansible Tower in versions before 3.7.2, where sensitive data can be exposed from the /api/v2/labels/ endpoint. This flaw allows users from other organizations in the system to retrieve any label from the organization and also disclose organization names. The highest threat from this… | |
| Modificada | Baja (3.3) | 0.24% | — | Redhat Ansible Tower | 27/5/2021 | 17/6/2026 | A flaw was found in Ansible Tower in versions before 3.7.2. A Server Side Request Forgery flaw can be abused by supplying a URL which could lead to the server processing it connecting to internal services or exposing additional internal services and more particularly retrieving full details in case of error. The… | |
| Modificada | Media (5.5) | 0.25% | — | Redhat Ansible Tower | 27/5/2021 | 17/6/2026 | A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower server is abused by supplying a URL that could lead to the server processing it. This flaw leads to the connection to internal services or the exposure of additional internal… | |
| Modificada | Media (5.5) | 0.44% | — | Redhat Ansible EngineDebian Linux | 27/5/2021 | 17/6/2026 | A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as the template caching action for the same file since no re-evaluation happens. The highest threat from this vulnerability would be that all passwords are exposed at once for… | |
| Modificada | Media (6.5) | 0.77% | — | Redhat SatelliteRedhat Satellite CapsuleTheforeman Foreman Ansible | 27/5/2021 | 17/6/2026 | A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the view. This flaw allows a malicious Satellite user to scan through the Job Invocation, with the ability to search for passwords and other sensitive data. This flaw affects tfm-rubygem-foreman_ansible… | |
| Modificada | Alta (7.1) | 0.27% | — | Redhat Ansible Tower | 27/5/2021 | 17/6/2026 | A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authentication. This flaw allows an attacker to obtain a refresh token that does not expire. The original token granted to the user still has access to Ansible Tower, which… | |
| Modificada | Baja (3.3) | 0.27% | — | Redhat Ansible Tower | 27/5/2021 | 17/6/2026 | A flaw was found in Ansible Tower when running jobs. This flaw allows an attacker to access the stdout of the executed jobs which are run from other organizations. Some sensible data can be disclosed. However, critical data should not be disclosed, as it should be protected by the no_log flag when debugging is… | |
| Modificada | Media (4.4) | 0.24% | — | Redhat Ansible Tower | 27/5/2021 | 17/6/2026 | A flaw was found in Ansible Tower when running Openshift. Tower runs a memcached, which is accessed via TCP. An attacker can take advantage of writing a playbook polluting this cache, causing a denial of service attack. This attack would not completely stop the service, but in the worst-case scenario, it can reduce… | |
| Modificada | Media (5.5) | 0.35% | — | Oracle VirtualizationRedhat AnsibleRedhat Ansible TowerRedhat Cisco Nx-os Collection+4 | 26/5/2021 | 17/6/2026 | A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality.… | |
| Modificada | Media (5.5) | 0.34% | — | Redhat AnsibleRedhat Ansible TowerFedoraproject Fedora | 26/5/2021 | 17/6/2026 | A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to… | |
| Modificada | Alta (7.5) | 2.1% | — | Redhat Ansible EngineRedhat Ansible Automation PlatformRedhat Ansible TowerDebian Linux | 29/4/2021 | 17/6/2026 | A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to… | |
| Modificada | Media (5.5) | 0.33% | — | Redhat AnsibleRedhat Ansible TowerFedoraproject Fedora | 1/4/2021 | 17/6/2026 | A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nodes, as well as being made visible on the controller node when run in verbose mode. These parameters were not protected by the no_log feature. An attacker can take… | |
| Modificada | Media (6.7) | 0.41% | 💥 PoC | Redhat Ansible Tower | 9/3/2021 | 17/6/2026 | A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the privilege from a low privileged user to the awx user from outside the isolated environment. The highest threat from this vulnerability is to data confidentiality and integrity as well… | |
| Modificada | Media (5.5) | 0.21% | — | Ceph-ansibleRedhat Ceph Storage | 8/12/2020 | 17/6/2026 | A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality. | |
| Modificada | Media (4.3) | 0.80% | — | Jenkins Ansible | 4/11/2020 | 17/6/2026 | Missing permission checks in Jenkins Ansible Plugin 1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Alta (7.5) | 1.4% | — | Ansible Collections Project Community.crypto | 29/10/2020 | 17/6/2026 | A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This directly impacts confidentiality | |
| Modificada | Media (5.5) | 0.32% | — | Redhat Ansible | 5/10/2020 | 17/6/2026 | A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed. Files would remain in the bucket exposing the data. This issue affects directly data confidentiality. |