Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

223 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)5.2%—Redhat AnsibleDebian Linux20/2/202017/6/2026
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.
ModificadaMedia (5.5)0.38%—Redhat Ansible20/2/202017/6/2026
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb http://user:pass@server:port/" format.
ModificadaCrítica (9.8)3.5%—Redhat Ansible18/2/202017/6/2026
Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansible managed host and providing a crafted fact, as demonstrated by a fact with (1) a trailing " src=" clause, (2) a trailing " temp=" clause, or (3) a trailing " validate="…
ModificadaCrítica (9.8)3.5%—Redhat Ansible18/2/202017/6/2026
Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which allows remote attackers to execute arbitrary code via (1) crafted lookup('pipe') calls or (2) crafted Jinja2 data.
ModificadaAlta (7.5)1.2%—Redhat Ansible9/1/202017/6/2026
Ansible prior to 1.5.4 mishandles the evaluation of some strings.
ModificadaMedia (6.5)1.9%—Redhat AnsibleRedhat Ansible TowerRedhat Ceph StorageRedhat Cloudforms Management Engine+42/1/202017/6/2026
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
ModificadaMedia (5.3)1.1%—Redhat Ansible Tower19/12/201917/6/2026
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and the password contains the '#' character. This request would cause a socket error in RabbitMQ when parsing the password and an HTTP error code 500 and partial password disclose will occur in…
ModificadaMedia (5.5)0.31%—Redhat Ansible Tower19/12/201917/6/2026
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readable. These files include both the SECRET_KEY and the database backup. Any user with access to the Tower server, and knowledge of when a backup is run, could retrieve every credential stored in Tower.…
ModificadaAlta (8.2)1.5%—Redhat Ansible TowerRedhat Enterprise Linux19/12/201917/6/2026
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If the default admin user is still active, an attacker could guess the password…
ModificadaMedia (6.5)1.7%—Redhat AnsibleOpensuse Backports SLEOpensuse LeapRedhat Openstack26/11/201917/6/2026
ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
ModificadaAlta (8.4)0.24%—Redhat Ansible Tower26/11/201917/6/2026
A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license.
ModificadaMedia (6.5)1.9%—Redhat Ansible25/11/201917/6/2026
A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for all gcp modules is not setting no_log to True. Any sensitive data managed by that…
ModificadaMedia (6.5)1.5%—Redhat AnsibleDebian LinuxOpensuse Backports SLEOpensuse Leap22/11/201917/6/2026
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.
ModificadaMedia (5.5)0.42%—Redhat Ansible EngineRedhat Ansible Tower14/10/201917/6/2026
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result,…
ModificadaAlta (7.8)0.51%—Redhat Ansible EngineDebian LinuxOpensuse Backports SLEOpensuse Leap+18/10/201917/6/2026
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are…
ModificadaMedia (5.4)1.8%—Redhat AnsibleRedhat OpenstackDebian Linux30/7/201917/6/2026
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
ModificadaMedia (4.3)1.3%—Jenkins Ansible Tower30/4/201917/6/2026
A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doFillTowerCredentialsIdItems method allowed attackers with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.
ModificadaAlta (8.8)1.8%—Jenkins Ansible Tower30/4/201917/6/2026
A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through…
ModificadaAlta (8.8)1.5%—Jenkins Ansible Tower30/4/201917/6/2026
A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through…
ModificadaAlta (7.2)1.3%—Redhat Ansible Tower28/3/201917/6/2026
When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.
ModificadaMedia (4.2)0.53%—Redhat Ansible27/3/201917/6/2026
Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.
ModificadaMedia (5.5)2.5%—Artifex GhostscriptRedhat Ansible TowerRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+825/3/201917/6/2026
It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.
ModificadaMedia (5.5)2.5%—Artifex GhostscriptRedhat Ansible TowerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+725/3/201917/6/2026
It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.
ModificadaMedia (5.3)2.5%—Redhat AnsibleDebian LinuxRedhat Ansible EngineRedhat Openstack+53/1/201917/6/2026
ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.
ModificadaCrítica (9.8)1.1%—Redhat Ansible Tower3/1/201917/6/2026
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory…
Orbitaley — Vulnerabilidades