Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
222 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.9% | — | Redhat AnsibleRedhat Ansible TowerRedhat Ceph StorageRedhat Cloudforms Management Engine+4 | 2/1/2020 | 17/6/2026 | Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data. | |
| Modificada | Media (5.3) | 1.1% | — | Redhat Ansible Tower | 19/12/2019 | 17/6/2026 | A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and the password contains the '#' character. This request would cause a socket error in RabbitMQ when parsing the password and an HTTP error code 500 and partial password disclose will occur in… | |
| Modificada | Media (5.5) | 0.31% | — | Redhat Ansible Tower | 19/12/2019 | 17/6/2026 | A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readable. These files include both the SECRET_KEY and the database backup. Any user with access to the Tower server, and knowledge of when a backup is run, could retrieve every credential stored in Tower.… | |
| Modificada | Alta (8.2) | 1.5% | — | Redhat Ansible TowerRedhat Enterprise Linux | 19/12/2019 | 17/6/2026 | A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If the default admin user is still active, an attacker could guess the password… | |
| Modificada | Alta (8.4) | 0.24% | — | Redhat Ansible Tower | 26/11/2019 | 17/6/2026 | A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license. | |
| Modificada | Alta (7.2) | 2.0% | — | HP 260 G1 DM FirmwareHP 280 PRO G1 FirmwareHP 285 G2 FirmwareHP 340 G3 Firmware+98 | 5/11/2019 | 17/6/2026 | A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of privilege. The EFI_BOOT_SERVICES structure might be overwritten by an attacker to execute arbitrary SMM (System Management… | |
| Modificada | Media (5.5) | 0.42% | — | Redhat Ansible EngineRedhat Ansible Tower | 14/10/2019 | 17/6/2026 | A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result,… | |
| Modificada | Media (4.3) | 1.3% | — | Jenkins Ansible Tower | 30/4/2019 | 17/6/2026 | A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doFillTowerCredentialsIdItems method allowed attackers with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins. | |
| Modificada | Alta (8.8) | 1.8% | — | Jenkins Ansible Tower | 30/4/2019 | 17/6/2026 | A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through… | |
| Modificada | Alta (8.8) | 1.5% | — | Jenkins Ansible Tower | 30/4/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through… | |
| Modificada | Baja (3.3) | 0.24% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+173 | 10/4/2019 | 17/6/2026 | In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that after resuming from S3 sleep mode in various versions of BIOS for Lenovo… | |
| Modificada | Alta (7.2) | 1.3% | — | Redhat Ansible Tower | 28/3/2019 | 17/6/2026 | When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges. | |
| Modificada | Media (5.5) | 2.5% | — | Artifex GhostscriptRedhat Ansible TowerRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+8 | 25/3/2019 | 17/6/2026 | It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. | |
| Modificada | Media (5.5) | 2.5% | — | Artifex GhostscriptRedhat Ansible TowerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+7 | 25/3/2019 | 17/6/2026 | It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. | |
| Modificada | Crítica (9.8) | 1.1% | — | Redhat Ansible Tower | 3/1/2019 | 17/6/2026 | Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory… | |
| Modificada | Alta (7.8) | 0.36% | — | Redhat Ansible EngineRedhat Ansible TowerDebian LinuxSuse Package HUB | 23/10/2018 | 17/6/2026 | Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list. | |
| Modificada | Alta (8.8) | 4.4% | — | ParamikoRedhat Ansible TowerRedhat Virtualization HostRedhat Enterprise Linux Desktop+7 | 8/10/2018 | 17/6/2026 | Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity. | |
| Modificada | Crítica (9.8) | 97% | 💥 Exploit | Git-scm GITRedhat Ansible TowerRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+7 | 6/10/2018 | 17/6/2026 | Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a '-' character. | |
| Modificada | Alta (8) | 0.64% | — | Redhat Ansible Tower | 11/9/2018 | 17/6/2026 | A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level access to the database. | |
| Modificada | Media (6.5) | 0.60% | — | Redhat Ansible TowerRedhat Cloudforms Management Engine | 22/8/2018 | 17/6/2026 | Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that X-Forwarded-For header allows internal servers to deploy other systems (using callback). | |
| Modificada | Alta (8.8) | 0.90% | — | Redhat Ansible Tower | 22/8/2018 | 17/6/2026 | Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could exploit this by tricking already authenticated users into visiting a malicious site and hijacking the authtoken cookie. | |
| Modificada | Crítica (9.8) | 5.7% | — | Debian LinuxCanonical Ubuntu LinuxLibxcursorRedhat Ansible Tower+3 | 1/8/2018 | 17/6/2026 | _XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow. | |
| Modificada | Alta (8.8) | 3.8% | — | Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+4 | 28/7/2018 | 17/6/2026 | An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression. | |
| Modificada | Alta (8.8) | 3.8% | — | Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+4 | 28/7/2018 | 17/6/2026 | An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite. | |
| Modificada | Media (6.5) | 3.7% | — | Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+4 | 28/7/2018 | 17/6/2026 | An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames. |