« Volver al listado

Ansible

Ansible-core: vulnerabilidades y CVE

Ansible-core tiene 6 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses4
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-84714Alta (7.1)0.29%—23 sept 2026
—
CVE-2026-71465Baja (3.1)0.21%—23 sept 2026
—
CVE-2026-16493Alta (7.8)0.17%—21 jul 2026
A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator before user-supplied…
CVE-2026-11332Alta (7.8)0.22%—5 jun 2026
A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious…
CVE-2024-11079Media (5.5)0.50%—12 nov 2024
A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code…
CVE-2024-9902Media (6.3)0.26%—6 nov 2024
A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter3
  2. T1203 Exploitation for Client Execution2
  3. T1210 Exploitation of Remote Services2
  4. T1059.007 JavaScript1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Ansible