Search CVE reports


Toggle filters

31 – 40 of 83 results


CVE-2020-1739

Medium priority

Some fixes available 4 of 5

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node....

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-1738

Medium priority
Needs evaluation

A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-1737

Medium priority
Needs evaluation

A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-1736

Medium priority
Needs evaluation

A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-1735

Medium priority
Needs evaluation

A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-1734

Medium priority
Needs evaluation

A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-1733

Medium priority

Some fixes available 3 of 4

A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-14365

Medium priority
Needs evaluation

A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-14332

Low priority
Needs evaluation

A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-14330

Medium priority
Vulnerable

An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Vulnerable Vulnerable
Show less packages